Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium
A company is developing a security awareness program for its employees. They want to ensure that the training effectively changes employee behavior regarding phishing emails. Which metric would be MOST effective in assessing the success of this objective?
- ANumber of employees completing the training module.
- BEmployee scores on a post-training knowledge quiz.
- CPercentage reduction in clicks on simulated phishing emails.
- DNumber of security incident reports filed by employees.
Show answer & explanationAnswer & explanation
Correct answer: C. Percentage reduction in clicks on simulated phishing emails.
The objective is to change employee behavior regarding phishing. A reduction in clicks on simulated phishing emails directly measures this behavioral change, making it the most effective metric.
Why the other options are wrong
- A. Completion rates indicate participation, not necessarily behavioral change.
- B. Quiz scores measure knowledge retention, but not necessarily the application of that knowledge in real-world behavior.
- D. An increase in incident reports might indicate better reporting, but not necessarily a reduction in susceptibility to phishing.
Security Awareness Program Effectiveness Metrics
Quantifiable measures used to evaluate how well a security awareness program achieves its goals, particularly in changing employee behavior.
- Focus on behavioral changes, not just knowledge acquisition.
- Examples include phishing click rates, incident reporting rates, policy compliance.
- Baseline measurements are crucial for demonstrating improvement.
Memory trick: Measure Behavior, Not Just Knowledge.