Building an Effective Security Awareness Program ◾ 103
must be identified, fine-tuned, and periodically adjusted as conditions and priorities
change. Although there are no school solutions or etched-in-stone rules for deter-
mining who the target audiences are, here are some suggestions and guidelines.
Information Technology Providers—those who envision, develop, test, install,
repair, patch, maintain, tweak, implement, remove, replace, explain, document,
and answer questions and complaints regarding IT systems are definitely targets
for the awareness program. And don’t forget the people who audit and secure the
systems. Different subsets of the IT provider universe will need different security
elements emphasized, and the manner of delivery m