Platform X - Training Program: Standard

Describes the Standards related to the Platform X Training Program
  1. Purpose
    1. The purpose of this document is to provide role-based security training standards.
  2. Definitions
    1. Electronic Protected Health Information (ePHI): Any individually identifiable health information protected by HIPAA that is transmitted or stored in electronic media.
  3. Standards
    1. Prior to granting access to the information system, all users must complete role-based training.
      1. Administrators are responsible for identifying required and optional courses for each role.
      2. Training must address all relevant security features necessary to reduce the risk of improper access, uses and disclosures.
    2. Required and optional courses must be reviewed annually, and when new features or roles are introduced to the platform.
      1. When new required training is added to a role, all employees in that role must complete training within 30 days.
    3. Users must provide evidence of training completion.
    4. Administrators must verify and retain records on completion of training.
    5. Administrators must ensure that all users have knowledge of, and access to, training and other relevant security-related documentation
    6. Administrators must provide at least quarterly basic security awareness training to all users, topics include:
      1. Software patching
      2. Anti-virus and anti-malware software
      3. Login monitoring
      4. Password and MFA management
    7. Administrators must communicate, via quarterly security reminders, new and important issues. 
    8. Administrators must provide all users with contact information for the Security Official for the Information System. The Security Official should be contacted if there are any security issues.
  4. Applicable NIST Controls
    1. AT-1: Security Awareness and Training Policy and Procedures
    2. AT-2: Security Awareness Training
    3. AT-3: Role-Based Security Training
    4. AT-4: Security Training Records
  5. Related Standards, Policies and Procedures
    1. [Link for document 109136 is unavailable at this time]
    2. [Link for document 109051 is unavailable at this time]


KeywordsStandard, Platform X, Px, Training   Doc ID109052
OwnerMike C.GroupSMPH Research Informatics
Created2021-02-13 11:54:29Updated2024-08-19 10:28:04
SitesSMPH Research Informatics , SMPH Research Informatics TEST
Feedback  0   0