Certified Information Security Manager (CISM)Information Security GovernanceHard

A CISO is attempting to foster a stronger security-aware culture within an organization where security is often viewed as an impediment to business operations. Which of the following is the MOST effective approach to shift this organizational culture?

  1. AIncrease the budget for advanced security technologies to reduce reliance on human vigilance.
  2. BDistribute monthly security newsletters with technical tips and threat intelligence updates.
  3. CImplement mandatory, punitive measures for all security policy violations.
  4. DLaunch a comprehensive, continuous security awareness program that emphasizes the 'why' behind security.
Show answer & explanation

Correct answer: D. Launch a comprehensive, continuous security awareness program that emphasizes the 'why' behind security.

To shift an organizational culture, security awareness must go beyond mere rules. A comprehensive, continuous program that explains the business value and personal relevance ('the why') of security helps employees understand their role, fostering a more positive and proactive security culture.

Why the other options are wrong

  • A. While technology is important, it cannot fully replace human vigilance, and over-reliance on it may lead to a false sense of security and neglect of cultural aspects.
  • B. Newsletters are a component of awareness, but they are often passive and may not be sufficient on their own to drive a deep cultural shift, especially if they are overly technical.
  • C. Punitive measures alone can breed resentment and avoidance rather than genuine cultural change or understanding.

Security Culture Transformation

The process of changing an organization's collective attitudes, beliefs, and behaviors regarding information security, moving from a view of security as a burden to an understanding of it as an enabler and shared responsibility.

  • Requires continuous communication and education.
  • Emphasizes understanding the 'why' behind security.
  • Involves leadership support and positive reinforcement.

Memory trick: To change security culture, educate the 'why', not just the 'what'.

More Information Security Governance questions