ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium
A CISA is reviewing an organization's information security awareness training program. The CISA observes that while initial training is provided to all new hires, there is no annual refresher training or regular communication on emerging threats. What is the MOST likely consequence of this approach?
- AHigher risk of employees falling victim to evolving social engineering attacks.
- BChallenges in demonstrating due diligence to regulatory bodies.
- CIncreased difficulty in achieving ISO 27001 certification.
- DReduced employee morale due to perceived lack of security importance.
Show answer & explanationAnswer & explanation
Correct answer: A. Higher risk of employees falling victim to evolving social engineering attacks.
Cyber threats, especially social engineering techniques, are constantly evolving. Without ongoing training and communication, employees' security awareness will diminish over time, and they will not be informed about new and emerging threats, making them more susceptible to successful attacks.
Why the other options are wrong
- B. Demonstrating due diligence is a compliance outcome. The root cause and direct operational risk is the diminished human defense against threats.
- C. While continuous training is a component of ISO 27001, the most direct and operational consequence is the increased vulnerability to attacks.
- D. Employee morale is unlikely to be directly impacted by the absence of refresher training; rather, it affects their security posture.
Continuous Security Awareness
An ongoing program of security education, training, and communication designed to keep employees informed about current threats, security policies, and best practices, reinforcing a security-conscious culture.
- Initial training is not sufficient.
- Threat landscape constantly changes.
- Transforms employees into a strong defense layer.
Memory trick: Old training, new threats, big risks.