Quick Overview
- This standard sets the specific requirements for the security and privacy training and awareness that SFA must provide to its people.
- It carries out the goals in the SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy.
- It covers three areas: general literacy training and awareness, role-based training for higher-risk jobs, and keeping training records.
- It applies to everyone who uses SFA information resources, including staff, faculty, vendors, and contractors.
- These requirements are the minimum baseline SFA must meet; the university may choose to do more.
- Meeting this standard is mandatory unless a formal exception is granted.
Most security incidents start with a person, not a machine: a clicked phishing link, a misdirected email, or a file shared with the wrong people.
This standard makes sure everyone at SFA learns how to spot and avoid those risks. It requires the university to train new hires, refresh that
training every year, run regular awareness activities like phishing tests and newsletters, give extra training to people in higher-risk roles,
and keep records that prove the training happened. The goal is simple: help every user become a reliable first line of defense.
|
i
|
Policy vs. Standard
The matching policy (06-107.1) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps live in procedures.
|
Who This Applies To
This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users
of SFA information resources. If you have an SFA account or work inside SFA IT facilities (including vendors, visitors, and contingent workers),
the training requirements below apply to you unless a contract says otherwise.
|
i
|
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.
|
Who Is Responsible
Key roles & responsibilities
⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
- CISO & Office of Information Security: Develop or acquire and oversee security, privacy, and role-based training, working with Learning & Development teams, and annually certify training compliance to the state.
- Learning & Development Teams: Build or acquire and roll out the training programs in partnership with the Office of Information Security.
- Human Resources (HR) Managers: Identify who must be trained, handle onboarding, make sure new employees get initial and ongoing training, and keep the systems that track training completion secure and current.
- IT Security Managers: Make sure a training and awareness program exists, that its materials meet regulatory requirements, and that role-based training happens, including an annual review of completion.
- Security Training Leads: Coordinate, create, and run awareness and training activities alongside Learning & Development and other security stakeholders.
- Compliance & Privacy Officers (PO): Make sure users understand and follow privacy rules (local, national, and international) and that training materials cover the necessary privacy topics.
Full role definitions
Complete responsibilities for each role are in the attached standard PDF.
What This Standard Requires
The requirements are grouped into three areas. Expand any area for a plain-language summary of what it requires.
The official requirement numbers (like 06-107.1.4.1.1) are shown so you can match them to the attached PDF.
1 Literacy Training and Awareness
The training everyone gets
⌄
SFA must give every user basic security and privacy training, keep it fresh, and run regular awareness activities throughout the year.
- Provide security and privacy literacy training to every user during onboarding (within 30 days of their start date) and at least once every 12 months after that. The training must come from the Texas DIR list of Certified Cybersecurity Training Programs; if SFA builds its own, DIR must certify it each year (06-107.1.4.1.1).
- Review and update the training content at least every 36 months, or sooner when there are major system changes, policy or standard changes, industry framework changes, new threats or technology, or lessons learned from incidents and breaches (06-107.1.4.1.2).
- Run security and privacy awareness activities for all users at least once every 3 months, such as phishing simulation campaigns, in-person roadshows and events, or flyers and newsletters (06-107.1.4.1.3).
- Include core topics in the training at a minimum: hands-on practice with simulated incidents, how to spot and report insider threats, how to handle privacy violations under HIPAA, GDPR, and FERPA, how to recognize and report social engineering and suspicious behavior, the key policy and standard requirements, and current cyber threat trends (06-107.1.4.1.4).
|
!
|
Important
Annual security awareness training is required by Texas Government Code 2054.519. The training must be on the DIR certified list, and DIR offers a free certified course (in English and Spanish) that meets the requirement.
|
2 Role-based Training
Extra training for higher-risk jobs
⌄
People whose jobs carry more security or privacy risk need targeted training beyond the basics.
- Use a risk-based approach to identify roles that need deeper security knowledge, then provide that role-based training during onboarding (within 30 days of the start date) and at least once every 24 months thereafter (06-107.1.4.2.1).
- For anyone who handles confidential data such as Protected Health Information (PHI), include foundational privacy topics based on the Fair Information Practice Principles (FIPPs) in annual training: how PII is processed and disclosed transparently, HIPAA privacy and security rules, how to protect and handle confidential data, and how to handle and report privacy violations under HIPAA, GDPR, and FERPA (06-107.1.4.2.2).
3 Training Records
Tracking & proving completion
⌄
SFA must document who completed training, chase down anyone overdue, keep the records, and certify compliance to the state.
- Document and monitor all security and privacy training and awareness activity, including general and role-based training, using metrics for effectiveness, content produced, completion rates, and user engagement (06-107.1.4.3.1).
- Retain each person's training records according to SFA's record-retention rules, but for no less than 24 months (06-107.1.4.3.1).
- Enforce on-time completion using methods like automated overdue-training alerts, management or executive escalation, and HR involvement (06-107.1.4.3.1).
- Annually certify training compliance to the Texas Department of Information Resources (DIR) using its published method; the optional Texas by Texas (TxT) tool is available for tracking employee completion (06-107.1.4.3.1).
Conformance & Exceptions
Meeting this standard is mandatory and effective as of the standard's publication, unless a written contract says otherwise
or a formal exception has been granted. If a requirement genuinely can't be met and there's no workable fix, follow the exception process in
the SFA 06-107.1 policy; requests go to the SFA Chief Information Security Officer (CISO).
|
!
|
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.
|
Compliance Mapping (Reference)
For auditors and security staff. Everyday users can skip this section.
Frameworks & control references
⌄
Each requirement in this standard maps to one or more of these authoritative sources:
- NIST 800-53 Rev 5.1.1, primarily the AT (Awareness and Training) family, for example AT-2, AT-3, AT-4, and SR-11.
- TAC 202, for example 202.7(b)(4), 202.74(b)(2), and 202.74(b)(3).
- Texas DIR Security Controls Catalog, for example AT-2, AT-3, AT-4, and SR-11.
- NIST CSF (PR.AT-01, PR.AT-02) and NIST 800-171 (3.2.1, 3.2.2, 3.2.3).
- Privacy and data-protection frameworks: HIPAA (164.308(a)(5)(i), 164.530(b)), GDPR (Art 39(1)(b)), and GLBA (314.4(e)).
The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.
Related Policies & Standards
Supporting policy: SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy
Related standards:
Other references:
- UT System Incident Tracking Tool
- DIR Statewide Cybersecurity Awareness Training Guidance
- DIR Statewide Cybersecurity Awareness Training Video
- SFA 06-107 Controls Crosswalk Reference
Responsible office: Office of Information Security ·
Contact: itsecurity@sfasu.edu
|
📎
|
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.
|
Need Help?
Contact the IT Help Desk at
(936) 468-4357 (HELP) or submit a ticket at
help.sfasu.edu.
For questions about this standard, contact the Office of Information Security at
itsecurity@sfasu.edu.