Security information is communicated internally
Employees and relevant stakeholders need to receive security information appropriate to their role. Engineers need to know about secure coding standards. All staff need to know how to report a suspected incident. Finance needs to know about phishing risks. Internal security communication is how an organization converts policy documents into actual behaviour at the team level.
Implementation steps
- 1
Define what security information each audience needs
Map out the internal audiences (all employees, engineers, IT admins, executives, new hires) and what security information is relevant to each. All-staff needs: how to report incidents, phishing awareness, acceptable use. Engineers need: secure coding guidelines, vulnerability disclosure process. Executives need: risk posture summaries.
confluence notion - 2
Maintain a security knowledge base
Publish security policies, procedures, and guidelines in a location all employees can find. A dedicated security section in your internal wiki is ideal. Include: how to report an incident, the acceptable use policy, the data classification policy, and contact information for the security team.
confluence notion google-sites - 3
Establish a security communication channel
Create a dedicated channel for security announcements. Use it to push timely communications: new phishing campaigns, policy updates, required actions, drill results. Make it easy for employees to ask security questions and get answers. Record that announcements were sent.
slack microsoft-teams email
Evidence required
Security knowledge base or intranet
Evidence of a published, accessible internal security resource.
- - Confluence or Notion security page with policies and contacts
- - Security section in employee handbook
- - Internal wiki showing security procedures and guidelines
Records of security communications
Evidence that security information is actively communicated to employees.
- - Slack #security-announcements channel history
- - Email records of security policy updates sent to all staff
- - Security training completion notifications
Related controls
Security information is communicated to external parties
Communication and Information
Relevant security information is obtained and used
Communication and Information
Commitment to competence in security is demonstrated
Control Environment
Control activities are selected and developed to mitigate risks
Control Activities