A CISO is tasked with improving the information security culture within an organization where employees often bypass security controls for convenience. Previous awareness campaigns have had limited success. Which of the following approaches is MOST likely to effect a lasting change in organizational culture?
- AOutsourcing security awareness training to a third-party vendor.
- BIssuing more frequent email reminders about security policies and consequences.
- CImplementing stricter technical controls and blocking all non-compliant actions.
- DEstablishing a 'security champion' program to empower employees as security advocates.
Show answer & explanationAnswer & explanation
Correct answer: D. Establishing a 'security champion' program to empower employees as security advocates.
Establishing a 'security champion' program empowers employees from various departments to become security advocates. These champions can translate security concepts into relevant business contexts, foster peer-to-peer learning, and provide feedback, leading to a more organic and lasting improvement in security culture than top-down mandates or generic training.
Why the other options are wrong
- A. Outsourcing training might bring new content, but it often lacks the internal relevance and continuous engagement needed for deep cultural transformation.
- B. Email reminders are often ignored and have proven ineffective if previous awareness campaigns failed to change behavior.
- C. While technical controls are necessary, relying solely on them without addressing cultural issues can lead to employee resentment and attempts to circumvent controls.
Security Champion Program
A structured initiative to identify and empower employees from various departments to act as local security advocates, promoting secure practices, providing peer support, and bridging the gap between the security team and the broader workforce.
- Leverages peer influence and internal relevance.
- Fosters a 'bottom-up' approach to security culture.
- Provides a continuous feedback loop to the security team.
Memory trick: Turn employees into security superheroes, not just policy followers.