< !!! INTERNAL USE ONLY !!! >
Not for distribution directly to end user
Overview
This workflow defines how User Support should respond when a student receives an employee cybersecurity training email (Infosec IQ) in error.
The goal is to provide correct reassurance, document the interaction, and apply appropriate routing without escalating to unrelated departments or causing unnecessary concern.
Audience
User Support staff
Procedure
Step 1: When to Use This Workflow
Use this workflow when a student reports:
- Receiving an Infosec IQ email assigning employee cybersecurity training
- Receiving reminders for employee cybersecurity training
- Asking whether they must complete the training
- Providing screenshots that show employee‑only training modules
- Being clearly added in error (known internal misassignment pattern)
This workflow does not apply when:
- The user is employee-only and the training assignment appears legitimate
- The content is student cybersecurity training in Brightspace
- The issue involves MFA, phishing, or a security incident
- HR or Compliance training is involved
Step 2: Initial Verification
Before responding, confirm the following:
- The user’s affiliation is verified as student-only, employee-only, student-worker, or dual-affiliation
- Verify via Account Assist → Affiliation
- The email is an Infosec IQ employee training message
- The message was sent to the student’s CCBC email address
- The training is not the normal student cybersecurity content in Brightspace
- The situation matches a known internal misassignment pattern, if applicable
- If student-worker or dual-affiliation status exists, follow the IA verification path
If any check fails, stop and route appropriately.
Ticket Status and Documentation Requirements
Use In Progress while verifying the user’s affiliation, reviewing the reported message, and determining the correct workflow path.
Use On Hold – Pending Customer Response if waiting for the student to provide a screenshot or additional information.
For student-only misassignment cases, document the affiliation check, the Infosec IQ employee training message, and the reassurance provided.
For dual-affiliation or student-worker cases, document the affiliation found and route the ticket to Information Assurance (IA) for verification.
For suspicious or malicious-looking messages, do not advise the user to click links or open attachments. Follow the phishing or security incident workflow.
Do not close the ticket until the appropriate workflow path has been completed.
Step 3: What to Tell the Student
Phone Response
You received that cybersecurity training email by mistake. Students do not need to complete the employee training, and your account is not affected. You can safely ignore the message.
If additional reassurance is needed:
A few students were added in error. There’s nothing you need to do—just delete the email.
Ticket Response (Public Comment)
You received the employee cybersecurity training email by mistake. Students are not required to complete this training, and your account is not affected. You can safely ignore the message. Please let us know if you receive additional notices.
Step 4: STOP POINTS
User Support must not:
- Tell a student-only user to complete employee training, or advise completion before IA confirms the assignment is legitimate
- Escalate to HR, Payroll, Registrar, Systems, Desktop, Instructional Technology, or Brightspace
- Modify or remove training assignments
- Contact the vendor
- Suggest the student was hacked or at risk
- Speculate on system errors or assign blame
- Mention internal patterns to the student
Step 5: Routing Scenarios
Student‑only misassignment
- Reassure the student
- Add an internal note
- Close the ticket
- No escalation required
Training appears in Brightspace
- Use the Student Cybersecurity Training workflow
- Do not use this article
Suspicious or malicious‑looking email
- Do not advise clicking any links
- Follow the phishing or security incident workflow
Student worker or dual-affiliation user
- Reassure the user that their access is not impacted.
- Do not determine whether the assignment is legitimate.
- Route the ticket to Information Assurance (IA) for verification.
If IA confirms the training assignment is legitimate, advise the user to complete the training.
Internal Documentation
Use technician‑tone internal notes.
Student‑only case:
User is student‑only. User received Infosec IQ employee cybersecurity training email in error. User does not need to complete employee training. Provided reassurance. Matches known misassignment pattern. No escalation required.
Dual affiliation:
User appears to have both student and employee affiliation. User received the employee cybersecurity training email. Provided reassurance. Routed to IA for verification.
Customer‑Facing Responses
Standard response:
You received the employee cybersecurity training email by mistake. Students are not required to complete this training, and your account is not affected. You can safely ignore the message.
Dual‑affiliation response:
Because you appear to have both student and employee access, we are forwarding your question for verification. Your access is not impacted.
Suspicious email response:
Please do not click any links or open attachments until we verify the source. We will follow up shortly.
STOP POINT – Final Summary
If the user is student-only and the email is employee cybersecurity training:
- The student does not need to complete the training.
- No escalation is required.
- Provide reassurance.
- Add an internal note.
- Close the ticket.
Do not escalate to HR, Payroll, Registrar, Systems, Desktop, Instructional Technology, Brightspace, or employee‑training teams.
Escalate only when:
- The user has student-worker or dual-affiliation status → route to IA for verification.
- The email appears malicious → follow the phishing workflow.
If none of the above apply, the workflow is complete.