ssm.ro Docs
Security, Infrastructure & OperationsHuman Resources & Security

Security Awareness and Training

Security and data protection awareness and training program for staff

SSM.ro staff (Consultia Digital S.R.L.) receive ongoing training in information security and data protection, as a technical and organizational measure declared in the Privacy Policy.

Objectives

  • Reducing human risk (phishing, weak passwords, data manipulation)
  • Compliance with GDPR and security best practices
  • A "security by default" security culture in development and operations

Program components

ComponentContent
Onboarding trainingSecurity policies, confidentiality, use of 2FA and secrets
GDPR trainingApplicable legislation and data processing best practices — training and ongoing testing
Phishing awarenessRecognizing phishing attempts and social engineering
Secure codingSecure development practices, OWASP Top 10 (see Secure SDLC)
Operational hygieneCredential management, least privilege, incident reporting

Frequency

  • At hiring — mandatory initial training
  • Periodic — refresher and ongoing testing, in accordance with declared GDPR measures
  • Ad hoc — for major process, technology, or legislative changes

Relationship to other controls