Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is tasked with improving the organization's information security posture by enhancing security awareness and user behavior. Despite having formal policies and annual training, employees frequently bypass security controls for convenience. What is the MOST effective long-term strategy to address this cultural issue?

  1. AConduct an external audit of the security awareness program's effectiveness.
  2. BIncrease the frequency and severity of disciplinary actions for policy violations.
  3. CImplement more stringent technical controls to prevent all policy circumvention.
  4. DEstablish a 'Security Champion' program to foster a peer-driven security culture.
Show answer & explanation

Correct answer: D. Establish a 'Security Champion' program to foster a peer-driven security culture.

When formal training and policies are insufficient, a cultural shift is needed. A 'Security Champion' program empowers employees from various departments to act as security advocates, fostering a peer-driven, bottom-up approach that integrates security into daily operations and encourages positive behavior change through influence rather than just enforcement or technical blocks.

Why the other options are wrong

  • A. An external audit assesses effectiveness but doesn't provide a direct strategy for *improving* the culture and behavior from within.
  • B. Disciplinary actions can create resentment and a 'us vs. them' mentality, which is counterproductive to fostering a positive security culture.
  • C. While technical controls are necessary, relying solely on them to prevent all circumvention can hinder productivity and does not address the underlying cultural issue of convenience over security.

Security Champion Program

A program that designates and trains employees from various departments to act as security advocates and liaisons within their teams, fostering a peer-driven security culture and embedding security awareness more deeply into daily operations.

  • Empowers internal advocates.
  • Fosters peer-driven security culture.
  • Integrates security into daily work.

Memory trick: To change the tide, empower the people.

More Information Security Governance questions