cc2-2 Medium priority Security / Communication and Information

Security information is communicated internally

Employees and relevant stakeholders need to receive security information appropriate to their role. Engineers need to know about secure coding standards. All staff need to know how to report a suspected incident. Finance needs to know about phishing risks. Internal security communication is how an organization converts policy documents into actual behaviour at the team level.

Complete first: cc1-1

Implementation steps

  1. 1

    Define what security information each audience needs

    Map out the internal audiences (all employees, engineers, IT admins, executives, new hires) and what security information is relevant to each. All-staff needs: how to report incidents, phishing awareness, acceptable use. Engineers need: secure coding guidelines, vulnerability disclosure process. Executives need: risk posture summaries.

    confluence notion
  2. 2

    Maintain a security knowledge base

    Publish security policies, procedures, and guidelines in a location all employees can find. A dedicated security section in your internal wiki is ideal. Include: how to report an incident, the acceptable use policy, the data classification policy, and contact information for the security team.

    confluence notion google-sites
  3. 3

    Establish a security communication channel

    Create a dedicated channel for security announcements. Use it to push timely communications: new phishing campaigns, policy updates, required actions, drill results. Make it easy for employees to ask security questions and get answers. Record that announcements were sent.

    slack microsoft-teams email

Evidence required

Security knowledge base or intranet

Evidence of a published, accessible internal security resource.

  • - Confluence or Notion security page with policies and contacts
  • - Security section in employee handbook
  • - Internal wiki showing security procedures and guidelines

Records of security communications

Evidence that security information is actively communicated to employees.

  • - Slack #security-announcements channel history
  • - Email records of security policy updates sent to all staff
  • - Security training completion notifications

Related controls