Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is tasked with improving the information security culture within an organization where employees frequently bypass security controls for convenience. To effectively address this, the CISO decides to implement a security champion program. Which of the following is the MOST important outcome the CISO should aim for with this program?

  1. ATo create a network of trusted individuals who can promote security awareness and best practices from within their teams.
  2. BTo establish a formal reporting structure for all security incidents directly to the CISO.
  3. CTo identify and penalize employees who consistently violate security policies.
  4. DTo offload security responsibilities from the security team to departmental staff.
Show answer & explanation

Correct answer: A. To create a network of trusted individuals who can promote security awareness and best practices from within their teams.

The primary goal of a security champion program is to leverage internal advocates to foster a positive security culture. These champions act as trusted peers, promoting security awareness and best practices, thereby changing behaviors more effectively than top-down mandates.

Why the other options are wrong

  • B. Incident reporting is important but is a separate function from the primary objective of cultural change via champions.
  • C. While accountability is necessary, the main goal of a champion program is positive reinforcement and cultural influence, not punitive measures.
  • D. While champions assist, the program is not meant to replace the security team's core responsibilities.

Security Champion Program

A program that identifies and empowers employees from various departments to act as advocates and resources for information security within their respective teams.

  • Fosters a positive security culture.
  • Provides localized security expertise.
  • Improves security awareness and adoption of best practices.

Memory trick: Champions spread the security word from within.

More Information Security Governance questions