Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is tasked with improving the information security culture within an organization where security is often perceived as a barrier to productivity. Which of the following strategies is MOST effective in shifting this perception?

  1. APublicly reporting all security incidents and the disciplinary actions taken against employees involved.
  2. BIntegrating security champions into business units to promote security as an enabler and facilitate feedback.
  3. CImplementing stricter access controls and monitoring to enforce compliance.
  4. DLaunching a mandatory annual online security awareness training module for all employees.
Show answer & explanation

Correct answer: B. Integrating security champions into business units to promote security as an enabler and facilitate feedback.

Integrating security champions into business units is most effective because it embeds security within daily operations, promotes it as an enabler, and creates a two-way communication channel. This helps to shift the perception from security being a barrier to a collaborative effort.

Why the other options are wrong

  • A. Publicly shaming employees can create a culture of fear and distrust, hindering open communication about security issues.
  • C. Stricter controls can reinforce the perception of security as a barrier if not accompanied by communication and collaboration.
  • D. Mandatory training is a baseline, but often perceived as a chore and rarely shifts deep-seated cultural perceptions on its own.

Security Culture Transformation

The intentional process of changing an organization's shared values, beliefs, and practices around information security to foster a more proactive and positive security-aware environment.

  • Requires leadership buy-in and active participation.
  • Focuses on collaboration and empowerment, not just enforcement.
  • Integrates security into daily workflows and decision-making.

Memory trick: Turn security from a 'no' person into a 'know-how' partner.

More Information Security Governance questions