What do you suggest, to create the awareness of information security to all company employees and a refresher for those who have already attended the awareness shows before? I am new to this and need advice on how it should be addressed.
If you have company meetings, a brief security discussion provides a good way to reach a large majority of employees. E-mails, flyers, articles in newsletters, screen savers, mouse pads, etc. are also good ways to get refresher material out to everyone. A security section on the corporate intranet is also helpful. For new employees, security should be covered in their new employee orientation. Brown bags or security seminars are the most common methods to cover security awareness training that I have seen.
For more information on this topic, visit these other SearchSecurity resources:
Security Policies Tip: Creative user education
Security Policies Tip: Security awareness training
Executive Security Briefing: Security training -- A call to arms