• This page, Appendix A: Newly Hired Employee Cybersecurity Awareness Training Assignments by Course for Calendar Years 2020 and 2021, is   offered by
  • Office of the State Auditor

Appendix A: Newly Hired Employee Cybersecurity Awareness Training Assignments by Course for Calendar Years 2020 and 2021

This classification combines three situations that were not applicable to our audit, and were, therefore, not included in our calculations.

Table of Contents

Electronic Communications Policy Course

Situation

Initial Assignment

First Annual Refresher Assignment

Second Annual Refresher Assignment

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Assignments Completed Within 12 Months

50

44%

8

8%

0

0%

Assignments Not Completed

37

32%

0

0%

0

0%

Assignments Completed After 12 Months

0

0%

0

0%

0

0%

Not Assigned By Steamship Authority

27

24%

94

92%

94

100%

Subtotal: Required Employee Count

114

100%

102

100%

94

100%

Not Applicable*

86

 

98

 

106

 

Total: Employee Count

200

 

200

 

200

 

*      This classification combines three situations that were not applicable to our audit, and were, therefore, not included in our calculations: (1) the employee had not yet completed their assignment, but their expected 12-month completion requirement came after the end of the audit period (December 31, 2021); (2) the employee was terminated or became inactive before the Woods Hole, Martha’s Vineyard and Nantucket Steamship Authority assigned the course(s); or (3) the employee was terminated or became inactive before their 12-month assignment completion requirement. We consider best practice regarding the period for employees to complete cybersecurity awareness training to be within 30 days of assignment, not 12 months.

Email and Phishing Warning Course

Situation

Initial Assignment

First Annual Refresher Assignment

Second Annual Refresher Assignment

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Assignments Completed Within 12 Months

52

46%

8

8%

0

0%

Assignments Not Completed

36

32%

0

0%

0

0%

Assignments Completed After 12 Months

0

0%

0

0%

0

0%

Not Assigned By Steamship Authority

26

23%

92

92%

92

100%

Subtotal: Required Employee Count**

114

100%

100

100%

92

100%

Not Applicable*

86

 

100

 

108

 

Total: Employee Count

200

 

200

 

200

 

*      This classification combines three situations that were not applicable to our audit, and were, therefore, not included in our calculations: (1) the employee had not yet completed their assignment, but their expected 12-month completion requirement came after the end of the audit period (December 31, 2021); (2) the employee was terminated or became inactive before the Woods Hole, Martha’s Vineyard and Nantucket Steamship Authority assigned the course(s); or (3) the employee was terminated or became inactive before their 12-month assignment completion requirement. We consider best practice regarding the period for employees to complete cybersecurity awareness training to be within 30 days of assignment, not 12 months.

**    Discrepancy in total is due to rounding.

Safeguarding of Personal Information Policy Course

Situation

Initial Assignment

First Annual Refresher Assignment

Second Annual Refresher Assignment

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Assignments Completed Within 12 Months

49

43%

7

7%

0

0%

Assignments Not Completed

37

33%

0

0%

0

0%

Assignments Completed After 12 Months

1

1%

0

0%

0

0%

Not Assigned By Steamship Authority

26

23%

93

93%

93

100%

Subtotal: Required Employee Count

113

100%

100

100%

93

100%

Not Applicable*

87

 

100

 

107

 

Total: Employee Count

200

 

200

 

200

 

*      This classification combines three situations that were not applicable to our audit, and were, therefore, not included in our calculations: (1) the employee had not yet completed their assignment, but their expected 12-month completion requirement came after the end of the audit period (December 31, 2021); (2) the employee was terminated or became inactive before the Woods Hole, Martha’s Vineyard and Nantucket Steamship Authority assigned the course(s); or (3) the employee was terminated or became inactive before their 12-month assignment completion requirement. We consider best practice regarding the period for employees to complete cybersecurity awareness training to be within 30 days of assignment, not 12 months.

Date published: February 5, 2024

Help Us Improve Mass.gov  with your feedback

Please do not include personal or contact information.
Feedback