ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

An organization's information security management system (ISMS) includes a policy requiring annual security awareness training for all employees. During an audit, the CISA finds evidence that while training materials are up-to-date, a significant portion of employees (approximately 30%) have not completed the mandatory annual training for the current year. What is the MOST immediate risk to the organization?

  1. AReduced effectiveness of technical security controls due to user vulnerabilities.
  2. BIncreased cost of security incident response due to human error.
  3. CDifficulty in demonstrating due diligence in the event of a security breach.
  4. DFailure to achieve compliance with industry regulations requiring mandatory training.
Show answer & explanation

Correct answer: A. Reduced effectiveness of technical security controls due to user vulnerabilities.

Security awareness training is a critical human control designed to mitigate risks arising from user behavior. A significant portion of employees not completing mandatory training directly increases the likelihood of human-related security incidents (e.g., phishing, social engineering, improper data handling), thereby reducing the overall effectiveness of technical controls and increasing the organization's vulnerability.

Why the other options are wrong

  • B. While incident response costs may increase, the immediate risk is the increased likelihood of an incident occurring due to untrained staff.
  • C. Difficulty in demonstrating due diligence is a legal/reputational consequence, not the most immediate security risk from untrained employees.
  • D. Compliance failure is a consequence, but the most immediate and direct risk is the increased likelihood of a security breach.

Security Awareness Training Efficacy

Effective security awareness training ensures employees understand security policies and best practices, acting as a critical human control to reduce the risk of security incidents.

  • Mitigates human-related security risks.
  • Reinforces security policies and procedures.
  • Reduces the likelihood of successful attacks (e.g., phishing).

Memory trick: A chain is only as strong as its weakest link, and untrained users are often those links.

More Domain 2: Governance and Management of IT questions