CC Required Training Policy

Responsible office
Dean of the College
Responsible party
COO
Last revision
July 2026
Approved by
The Cabinet
Approval date
July 2026
Effective date
August 2026
Last review
July 2026
Additional references

Scope

All financial and administrative policies involving community members across campus, including volunteers are within the scope of this policy. If there is a variance between departmental expectations and the common approach described through college policy, the college will look to the campus community, including volunteers to support the spirit and the objectives of college policy. Unless specifically mentioned in a college policy, the college’s Board of Trustees are governed by their Bylaws.

Policy

  • New employees must complete an assigned required training program within 60 days of hire or their account will be suspended (see Consequences section).
  • All those with an individual CC account must complete the assigned required training program annually. CC will test the efficacy of the training program through periodic social engineering exercises.
  • Specialized Training: Some departments, like HR, Finance, Leadership, Security Management, and IT, may have unique security needs. You might need additional training if you're in one of these teams. The Administration will specify these needs, and the training should be completed in the same timeline as the general required training.
  • Supplemental training may be required in certain situations:
    • Security breaches that are tied to an individual's CC account.
    • Departments with regulatory compliance requirements, such as FERPA, GLBA, and PCI DSS.
    • Failure of a simulated security challenge as defined by taking one or more of the following activities on a simulated phishing test:
      • Clicking on the link in the phishing test
      • Opening an attachment from the phishing
      • Replying to a phishing test email
      • Entering data on a phishing email landing page
      • Transmitting any information as part of a vishing (Phone Phishing) test
    • A significant shift in job responsibilities which demands heightened security knowledge.

Procedures

Consequences for failing to complete training

  • If someone misses the required training deadline, their account will be automatically suspended. 
  • To restore access, they must contact the ITS Solutions Center and explain they need access to complete the training.
  • Once access is re-established, there is a 48-hour window to complete the training. Failure to do so will lead to another suspension. 
    • Subsequent reactivation requires approval from HR/Student Conduct Office or the immediate supervisor.

Security Testing Through Simulated Exercises

From time to time, we'll simulate potential threats. These could be deceptive emails (phishing), misleading phone calls (vishing), or on-site assessments. 

  • Timing of Tests: The exact timing remains unpredictable. Like real-world security threats pop up when we least expect them, our tests will too. 
  • Subjects of Testing: While everyone will get tested, sometimes we zoom in on specific departments or folks, especially if we've noticed a specific risk, or through other institutions who are reporting a heightened risk in specific areas.
  • Purpose: After our drills, we look at how we did. We'll provide more training where needed. 

  What Counts as an ITS "Failure"?

Generally, interacting with an actual phishing message in any way damages CC (other than opening it, which is unavoidable in many cases). We need you to be able to tell a phishing message from a legitimate one, so our tests are based on real phishing messages that have been turned into tests. Accordingly, a failure on our test is any of the following circumstances.

  • Not finishing required training on time
  • Not passing a security test (those fake “drill” emails or calls)
  • Examples of failing a security test:
    • Clicking on a link in a test email.
    • Responding with any details to that email.
    • Opening a fake attachment.
    • Turning on macros in a test attachment.
    • Filling in details on a fake webpage from the test.
    • Sharing any information during a fake phone call (vishing).
  • Even if there are many missteps in one test, we'll only count it as one "failure."

Sometimes, ITS might decide that a recorded "failure" was a mistake. If that happens, it won't count against you.

The following table outlines the penalty for failures. The CC ITS team may take steps not listed here to reduce an individual's risk to Colorado College.

*Note that employees are held to a higher standard than other accounts because of their level of access to sensitive and restricted data. 

Failure Count

Resulting Level of Remediation Action

First Failure

End-user notified and their mistake is explained to them along with noting that this counts as a failure. Supervisor also noted, and end-user attends additional training.

Second Failure

End-user and supervisor attend in-person training with CC ITS.

Third and subsequent Failures

Additional training/technical controls at the discretion of leadership. HR initiates disciplinary action, including but not limited to suspension and/or termination.

Fourth and subsequent Failures

Additional training/technical controls at the discretion of leadership. HR initiates disciplinary action, including but not limited to suspension and/or termination.


What counts as an ITS "Pass"

At CC, when our team members take the right steps, it's noted as a "Pass." Here's what you can do to earn one:

  • Training: Finish the required CC training within the time given.
  • Spotting Fake Attacks: If you identify a phishing email, report it by forwarding it to its@coloradocollege.edu with the phrase “scam report”
  • Avoiding Mistakes: Not slipping up during a security test (like not falling for our test emails) counts as a Pass.

Responsibilities and Accountabilities

A structured approach to information security is critical for the organization. Here's a breakdown of the roles and responsibilities associated with this policy:

Chief Operations Officer (COO):

  • Holds accountability for orchestrating an effective required training program.
  • Ensures all employees are informed and equipped to safeguard both the organization's and our community members' environment.

Human Resources (HR):

  • Collaborates with other departments to select required training to facilitate proper awareness and training sessions.
  • These modules and/or sessions are aimed at enlightening staff about their duties, as outlined in various policies, regulations, contracts, and more.

Information Technology Services (ITS):

  • Crafts and sustains an extensive collection of information security guidelines, which encompasses this policy.
  • Tracks and monitors employees who do not complete the required training and takes away access to CC systems.

Managers:

  • Ensure teams under their purview actively participate in the required training initiatives.
  • Ensure that all employees under their charge are up-to-date with their required training.

All employees, contractors and volunteers:

  • Personally responsible for completing all required training modules by the due date.
Report an issue - Last updated: 08/06/2026