Security, Infrastructure & OperationsHuman Resources & Security
Security Awareness and Training
Security and data protection awareness and training program for staff
SSM.ro staff (Consultia Digital S.R.L.) receive ongoing training in information security and data protection, as a technical and organizational measure declared in the Privacy Policy.
Objectives
- Reducing human risk (phishing, weak passwords, data manipulation)
- Compliance with GDPR and security best practices
- A "security by default" security culture in development and operations
Program components
| Component | Content |
|---|---|
| Onboarding training | Security policies, confidentiality, use of 2FA and secrets |
| GDPR training | Applicable legislation and data processing best practices — training and ongoing testing |
| Phishing awareness | Recognizing phishing attempts and social engineering |
| Secure coding | Secure development practices, OWASP Top 10 (see Secure SDLC) |
| Operational hygiene | Credential management, least privilege, incident reporting |
Frequency
- At hiring — mandatory initial training
- Periodic — refresher and ongoing testing, in accordance with declared GDPR measures
- Ad hoc — for major process, technology, or legislative changes
Relationship to other controls
- Incident reporting by staff feeds into the Incident Response Procedure.
- Secure coding practices are applied through the Secure SDLC and OWASP Top 10.
- Conduct obligations are detailed in the Code of Conduct.