Certified Information Security Manager (CISM)Information Security GovernanceHard

During a routine audit, it is found that several employees are sharing credentials for access to a critical financial application, violating organizational policy. The CISO needs to address this issue by reinforcing organizational culture. Which of the following actions is MOST likely to be effective in changing this behavior long-term?

  1. AImplement stricter technical controls to prevent credential sharing, such as multi-factor authentication (MFA).
  2. BConduct a refresher training session on the policy, emphasizing the disciplinary consequences of credential sharing.
  3. CCommunicate the specific risks and potential business impacts of credential sharing, including real-world examples.
  4. DDisable the accounts of all employees found to be sharing credentials immediately.
Show answer & explanation

Correct answer: C. Communicate the specific risks and potential business impacts of credential sharing, including real-world examples.

To change long-term behavior and reinforce culture, employees need to understand *why* a policy exists and the *impact* of non-compliance. Communicating risks and business impacts helps contextualize the policy, fostering a sense of shared responsibility rather than just compliance to rules.

Why the other options are wrong

  • A. MFA is a good technical control, but relying solely on technical enforcement without addressing the cultural 'why' may lead to users finding workarounds or resenting the controls.
  • B. Emphasizing disciplinary consequences can deter, but without understanding the underlying risks, it may not foster a genuine cultural shift or proactive adherence.
  • D. Immediate account disablement is a punitive measure. While sometimes necessary, it can demotivate and does not address the underlying cultural issue or educate employees on the importance of the policy for long-term change.

Cultural Reinforcement (Security)

The process of strengthening and embedding desired information security behaviors and values within an organization's culture through communication, education, leadership example, and positive reinforcement.

  • Focuses on understanding the 'why' behind policies.
  • Builds a sense of shared responsibility.
  • More effective for long-term change than purely punitive measures.

Memory trick: To change behavior, illuminate the 'why' and its real-world impact.

More Information Security Governance questions