top of page

Implement Policies and Procedures for Personnel to Implement your ISP


Employee Training


The greatest threat to customer data security is located between the monitor and the chair – in other words, your own employees. Therefore, you need policies and procedures, contained in your ISP, and training for all your employees on how your ISP impacts their duties. This training should occur at initial hiring and be repeated at least annually thereafter. Everyone, for example, needs to know what to do if a completed credit app is found on the showroom floor.


Basic Safeguards Training


Basic Safeguards training should cover the substance of the Rule itself, why customer and dealership data needs to be protected, and the elements of your dealership’s ISP. Receipt and acknowledgment of your ISP by every employee should be part of this and is most easily accomplished electronically.


Phishing Awareness


Phishing awareness training is where fake email attacks are periodically sent to your employees that have dealership email addresses. If someone clicks through the bait, that fact is recorded and remedial training can be applied.


QI and IT Personnel


In addition to this standard employee training, your QI and IT personnel need ongoing training to remain current on evolving threats and security developments. Because the occurrence and effectiveness of this training must be verified, archived testing should be a part of the process.


Remember, you’re only as secure as your least-trained employee, so train everyone – and keep them trained.




Connect with us

  • LinkedIn
  • YouTube

Disclaimer: The content on this website has been compiled for educational purposes only and is not intended as legal advice. The information on this website may not be current, and no warranty is made as to the accuracy of its contents. Providing access to the information and other content on this website does not comprise the providing of legal advice and does not create any attorney-client relationship. Mosaic Compliance Services, LLC, and Mosaic Cyber Security, LLC, are not law firms and do not provide legal advice.  You should consult with your own attorney for legal advice regarding the topics raised on this website.  

Mosaic Compliance Services logo white

5584 Rio Vista Dr, Clearwater, FL 33760

© 2024 by Mosaic Compliance Services, LLC

bottom of page