Security Awareness and Information Sharing. An organization depends on more than technology for implementing IT Security. Raising awareness of security and communications are equally as important. The commonwealth's CISO has implemented a security communication process to address awareness and communication. In addition to standardized and mandatory annual security awareness training for all commonwealth employees, the commonwealth has established CISO roundtable collaborative group comprised of agency ISO's and professionals. The session is chaired by the Chief Information Security Officer provides a forum for multi-directional information sharing among agencies on a quarterly basis.
Additionally, the Pennsylvania Information Sharing and Analysis Center (PA-ISAC) has been established to disseminate cyber security advisories, cyber security awareness bulletins, and information sharing with state and various levels of local government. The mission of PA-ISAC, consistent with the objectives of the National Strategy to Secure Cyberspace, is to provide a common mechanism for raising the level of cyber security readiness and response within the Commonwealth of Pennsylvania. The PA-ISAC provides a central resource for gathering information on cyber threats to critical infrastructure throughout the Commonwealth and provides two-way sharing of information between and among state local governments.