b)
the need to become familiar with and comply with applicable information security rules and
obligations, as defined in policies, standards, laws, regulations, contracts and agreements;
c) personal accountability for one’s own actions and inactions, and general responsibilities towards
securing or protecting information belonging to the organization and external parties;
d) basic information security procedures (such as information security incident reporting) and
baseline controls (such as password security, malware controls and clear desks);
e) contact points and resources for additional information and advice on information security matters,
including further information security education and training materials.