30.33 - Information Security Training & Awareness
Owner:
- Position: Vice President of Information Technology and Chief Information Officer, Information Technologies
- Email: oit-security@uidaho.edu
Last updated: July 13, 2026
Contents:
- A. Purpose
- B. Scope
- C. Definitions
- D. Policy
- E. Non-Compliance
- F. Exceptions
- G. Contact Information
- H. References
A. Purpose. The data and systems every university account has access to are valuable to attackers. This policy establishes the training requirements for information security at the University. Information security training helps ensure compliance with regulatory and contractual requirements, but it is also important for university affiliates to understand the specific risks to the university's information and how their role and access impact those risks. By understanding the risks and how to respond to them, employees can help to protect the confidentiality, integrity, and availability of the university's data.
B. Scope. This policy applies to all university accounts. Security literacy training and simulated phish requirements only apply to those currently employed by the university, or other affiliated individuals using an employee account.
The scope of this policy does not supersede approved system security plans, laws, regulations, or contractual limitations or requirements.
C. Definitions.
C-1. Account holder: An individual with credentials provided to authenticate - a specific account.
C-2. Awareness campaign: Awareness campaigns are communications or events intended to raise awareness of security issues which may be direct or broad in target audience.
C-3. Context-based training: Trainings on Specific tools or data to address additional risks and challenges which extend past what is covered in the Security Literacy trainings.
C-4. Employee account: Any individual account used to perform work on behalf of the university. Typically, this only includes accounts ending with @uidaho.edu.
C-5. Event-Based training: Event-based trainings are a broad category of trainings that include open forums, capture the flag, or other simulated or practical training events.
C-6. Information Security Literacy training: Information security literacy training is a general-purpose training for all employees regarding security concepts necessary to promote the security of data and systems.
C-7. Information Sharing and Analysis Centers (ISACs): Organization of organizations for sharing threat information and other relevant security information.
C-8. Phish: A method of social engineering where a legitimate individual is impersonated to convince victims to disclose information.
C-9. Practical training: Practical trainings are real-world examples or simulations of cybersecurity principles presented in an interactive way.
C-10. Security alert: A specific type of awareness campaign informing specific individuals of a risk or potential risk.
C-11. Simulated phishing: Much like other emergency simulations or drills, Phishing campaigns are real-world phishing messages which have been sanitized to allow the university to practice it’s phish response.
C-12. System Security Plan: A formal document outlining how a system implements security controls.
C-13. Training: Any formal verified methodology of educating one or more individuals. Acceptable training types include videos, open forums, simulations, readings, practical exercises, evaluations, or comprehension verification.
C-14. Vendors: Organizations from which the University of Idaho is receiving goods or services.
D. Policy.
D-1. Information Security Literacy training
- All employee account holders must complete the Security Literacy trainings within 30 days of their start date and on an annual basis.
- The Office of Information Technology (OIT) and Employee Development and Learning (EDL) jointly choose, deliver, and track the training.
- Access to systems will be automatically restricted if required trainings are not completed.
- If university security policies or standards change in an impactful way, new training or communications are required to cover the changes.
D-2 . Context based training.
- Data stewards, as defined by APM 30.11, are authorized to require specific trainings for access to data under their purview regardless of the system it is stored in.
- Application owners are authorized to require trainings specific to their application.
- Both data stewards and application owners are authorized to restrict access pending the completion of training.
- In the event a system is changed, the data steward must ensure the training is updated as appropriate.
D-3. Practical training and awareness campaigns. These trainings are intended to help maintain an advanced level of awareness of security risks. This assists the university by keeping its personnel informed about how to identify threats and respond to them appropriately.
-
Simulated Phishing campaigns
: These trainings are delivered to university account holders to rehearse identifying and reporting phishing emails.
-
Campaigns:
- OIT Security will send phishing emails to a randomized sample of account holders as often as monthly.
- Participation in a campaign is successful when the account holder has identified and reported the phishing message.
- Failure to report a message may result in an account being included in the next phishing campaign.
- Outside of OIT Security, reports will only be shared as required for compliance and in an aggregate, anonymized fashion unless required by Office of General Counsel or relevant VP/Provost.
- Supplemental or alternative campaigns with alternate rules may be sent upon request by a university vice president or the Provost.
- Simulated phishing campaigns may only be authorized by the VP of IT/CIO, or CISO.
-
Campaigns:
- Event based trainings: These trainings can be used in tandem or in replacement of other trainings, such as a training exercise put on by a vendor in replacement of existing training courses for a specific tool. These can only be used as replacements when approved by OIT Security, the data steward, or the application owner in the case of context specific trainings.
- Awareness campaigns : OIT Security will perform awareness campaigns as deemed appropriate by the OIT Security Office. These campaigns will be used to raise awareness for specific risks to the university, changes to policy and standards, or general security awareness.
-
Security Alerts
: OIT Security will monitor relevant sources of security alerts including but not limited to major UI vendors, Information Sharing and Analysis Centers (ISACs), as well as public and contracted sources.
- Individuals who are responsible for maintaining systems, applications, or services provided by or that rely on third party services must monitor channels from those third parties for security alerts and take appropriate action.
- Whichever party receives these alerts will inform relevant parties, including OIT Security, of security threats to the best of their abilities.
E. Noncompliance. Noncompliance with this policy may result, depending upon the nature of the noncompliance, in the user’s account or access being suspended to U of I technology resources as stated in Section B.3 of APM 30.12 ( Acceptable Use of Technology ).
F. Exceptions. Requests for exceptions to this policy may be submitted through the OIT Support Portal. The Chief Information Security Officer will assess the risk and make a recommendation to the Vice President for Information Technology and Chief Information Officer. Exceptions must be reviewed for reauthorization on no less than an annual basis.
G. Contact Information. The OIT Information Security Office ( oit-security@uidaho.edu ) can assist with questions regarding this policy and related standards. Questions should be submitted through the OIT Support Portal .
Questions regarding the trainings can be directed to Employee Development and Learning (EDL).
H. References.
- UI APM 30.11 - University Data Classifications and Standards
- UI Standards - Standards for Data Classifications
- UI FSH 3185 - Employee Work-Related Education
- UI APM 45.21 - Responsible Conduct of Research Training
- NIST 800-171r2 section 3.2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST 800-171r3 section 3.2 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- 16 CFR § 314 - STANDARDS FOR SAFEGUARDING CUSTOMER INFORMATION (GLBA)
- 45 CFR § 160 - GENERAL ADMINISTRATIVE REQUIREMENTS (HIPAA)
- 34 CFR § 99 - FAMILY EDUCATIONAL RIGHTS AND PRIVACY (FERPA)
- State of Idaho Law – Title 67, Chapter 8
Version History
2026 July . Interim Approved on July 13, 2026. Complete replacement of the prior Banner Training and Authorization policy, transforming a system-specific access and training requirement into a comprehensive, enterprise-wide Information Security Training and Awareness policy.
2013. Updates to contact information and committee wording revisions for clarity.
2005