• This page, Appendix B: Existing Employee Cybersecurity Awareness Training Assignments by Course for Calendar Years 2020 and 2021, is   offered by
  • Office of the State Auditor

Appendix B: Existing Employee Cybersecurity Awareness Training Assignments by Course for Calendar Years 2020 and 2021

These assignment designations (i.e., first, second, and third) are only for those assignments administered to existing employees during the period November 1, 2019 through December 31, 2021.

Table of Contents

Electronic Communications Policy Course

Situation

First Annual Refresher Assignment

Second Annual Refresher Assignment

Third Annual Refresher Assignment

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Assignments Completed Within 12 Months

188

28%

111

25%

10

3%

Assignments Not Completed

261

39%

3

1%

0

0%

Assignments Completed After 12 Months

115

17%

0

0%

0

0%

Not Assigned By Steamship Authority

99

15%

332

74%

344

97%

Subtotal: Required Employee Count**

663

100%

446

100%

354

100%

Not Applicable*

48

 

265

 

357

 

Total: Employee Count

711

 

711

 

711

 

*      This classification combines three situations that were not applicable to our audit, and were, therefore, not included in our calculations: (1) the employee had not yet completed their assignment, but their expected 12-month completion requirement came after the end of the audit period (December 31, 2021); (2) the employee was terminated or became inactive before the Woods Hole, Martha’s Vineyard and Nantucket Steamship Authority assigned the course(s); or (3) the employee was terminated or became inactive before their 12-month assignment completion requirement. We consider best practice regarding the period for employees to complete cybersecurity awareness training to be within 30 days of assignment, not 12 months.

**    Discrepancy in total is due to rounding.

†      These assignment designations (i.e., first, second, and third) are only for those assignments administered to existing employees during the period November 1, 2019 through December 31, 2021.

Email and Phishing Warning Course

Situation

First Annual Refresher Assignment

Second Annual Refresher Assignment

Third Annual Refresher Assignment

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Assignments Completed Within 12 Months

196

30%

115

26%

11

3%

Assignments Not Completed

258

39%

2

0%

0

0%

Assignments Completed After 12 Months

111

17%

0

0%

0

0%

Not Assigned By Steamship Authority

97

15%

330

74%

344

97%

Subtotal: Required Employee Count**

662

100%

447

100%

355

100%

Not Applicable*

49

 

264

 

356

 

Total: Employee Count

711

 

711

 

711

 

*      This classification combines three situations that were not applicable to our audit, and were, therefore, not included in our calculations: (1) the employee had not yet completed their assignment, but their expected 12-month completion requirement came after the end of the audit period (December 31, 2021); (2) the employee was terminated or became inactive before the Woods Hole, Martha’s Vineyard and Nantucket Steamship Authority assigned the course(s); or (3) the employee was terminated or became inactive before their 12-month assignment completion requirement. We consider best practice regarding the period for employees to complete cybersecurity awareness training to be within 30 days of assignment, not 12 months.

**    Discrepancy in total is due to rounding.

†      These assignment designations (i.e., first, second, and third) are only for those assignments administered to existing employees during the period November 1, 2019 through December 31, 2021.

 

Safeguarding of Personal Information Policy Course

Situation

First Annual Refresher Assignment

Second Annual Refresher Assignment

Third Annual Refresher Assignment

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Employee Count

Percentage of Required Employee Count to Total

Assignments Completed Within 12 Months

180

27%

107

24%

9

2%

Assignments Not Completed

272

41%

2

0%

0

0%

Assignments Completed After 12 Months

110

17%

0

0%

0

0%

Not Assigned By Steamship Authority

100

15%

344

76%

357

98%

Subtotal: Required Employee Count

662

100%

453

100%

366

100%

Not Applicable*

49

 

258

 

345

 

Total: Employee Count

711

 

711

 

711

 

*      This classification combines three situations that were not applicable to our audit, and were, therefore, not included in our calculations: (1) the employee had not yet completed their assignment, but their expected 12-month completion requirement came after the end of the audit period (December 31, 2021); (2) the employee was terminated or became inactive before the Woods Hole, Martha’s Vineyard and Nantucket Steamship Authority assigned the course(s); or (3) the employee was terminated or became inactive before their 12-month assignment completion requirement. We consider best practice regarding the period for employees to complete cybersecurity awareness training to be within 30 days of assignment, not 12 months.

†      These assignment designations (i.e., first, second, and third) are only for those assignments administered to existing employees during the period November 1, 2019 through December 31, 2021.

 

Date published: February 5, 2024

Help Us Improve Mass.gov  with your feedback

Please do not include personal or contact information.
Feedback