Skip to main content

Appendix J: Communications Plan - Template

 

Healthcare and Public Health Sector Cybersecurity Framework Implementation Guide
 

Table 16. Communication Vehicles
 
Vehicle
Target
Communication VehiclePurpose/ContentIntended AudienceDetailsFrequencyStrategyResponsible Party
All 
Audiences
Corporate-wide E-mail
Framework Announcement Updates
All Once 
 
Enterprise-wide 
Web-based Collaborative PlatformOpen repository for all project materials, including Processes, workflows, templates, newsletters, contact lists, presentations, and Information Security materialsAll employees interested in learning about Information Security Processes Monitor for updatesEnterprise-wide and targeted 
Security TrainingInformation Security Awareness TrainingAll identified personnel
As
scheduled
Initial/Annually 
 
Targeted 
Security BulletinsNewsletter announcing successes, activities, items of interest, etc. to be posted to the PortalAll personnel
As
scheduled
OngoingCorporate-wide and targeted 
Leadership TeamOne-on-One meetings/ conversationsTwo-way exchange on Information Security Initiatives, benefits, and progress (high-level)Leadership TeamOngoingPeriodicTargeted 
 
Executive Sponsor 
 
CustomersPress ReleasePress Release announcing any applicable Information Security announcementsAllAs ApplicableOnceInternal/ External audiencesCommunications Team 
 
Security Assessment ParticipantsTemplatesTemplates used for DocumentsAll usersOngoingAs NeededCorporate-wide and targetedSecurity Officer
Lessons LearnedMeeting for participants after delivery of critical milestones to discuss what went well, what could have gone better, and what to do differently next timeAssessment ParticipantsASAPAs needed 
 
Corporate-wide and targeted 
 
Security Officer
Post Assessment ReviewsReviews of assessment outcomesAssessment ParticipantsAssessment scheduleAs scheduledTargeted 
 
Security Officer
E-mail Distribution ListDistribution Lists for targeted communications to be updated frequently and stored on the portalAssessment ParticipantsImmediatelyOngoing 
 
TargetedSecurity Officer 
 
SharePoint or Another Repository PlatformRepository for working documentsTargetedOngoingPeriodicTargetedSecurity Officer 
 
Corrective/ Preventive NotificationNotification of service improvement activities (corrective/preventive/non-conformance actions), progress, and statusAssessment ParticipantsOngoingOngoingTargetedSecurity Officer
Team MeetingsForum to share knowledge, status, and to promote coordinationAssessment ParticipantsOngoingAs neededTargetedSecurity Officer

<< Back