ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium
During an audit of an organization's human resources management, the CISA notes that security awareness training is conducted only for new hires and is not repeated annually for existing employees. What is the MOST significant risk associated with this practice?
- ADifficulty in obtaining cyber insurance coverage.
- BErosion of the organization's security posture over time.
- CIncreased cost of onboarding new employees.
- DDecreased employee satisfaction due to lack of professional development.
Show answer & explanationAnswer & explanation
Correct answer: B. Erosion of the organization's security posture over time.
Security awareness is not a one-time event; threats evolve, and human memory fades. Without regular, ongoing training, employees' understanding of security policies and best practices will diminish, leading to a weakened human firewall and an increased susceptibility to social engineering attacks, phishing, and other security incidents, thereby eroding the overall security posture.
Why the other options are wrong
- A. While poor security can impact insurance, the direct and most significant risk is the internal weakening of defenses.
- C. Onboarding costs are unrelated to the lack of recurring training for existing staff.
- D. While professional development is important, the primary risk of inadequate security training is not employee satisfaction but rather the direct impact on security.
Continuous Security Awareness
An ongoing program designed to educate all employees regularly about current information security threats, policies, and best practices to maintain a strong security culture.
- Addresses evolving threat landscape.
- Reinforces security behaviors.
- Crucial for human element of security.
Memory trick: Security knowledge isn't a 'set it and forget it'; it's a 'learn and refresh it'.