Certified Information Security Manager (CISM)Information Security ProgramMedium
A CISO is developing an information security awareness and training program. To ensure the program is effective and addresses the most significant human-related risks, which of the following is the MOST important input for its content development?
- AResults from the organization's latest risk assessment and incident reports.
- BIndustry-standard security awareness modules.
- CRegulatory requirements for mandatory annual security training.
- DFeedback from a survey of employee preferences for training formats.
Show answer & explanationAnswer & explanation
Correct answer: A. Results from the organization's latest risk assessment and incident reports.
An effective security awareness program should be tailored to the organization's specific risks. The latest risk assessment identifies what those risks are, and incident reports highlight where human behavior has contributed to past security failures, making these the most relevant inputs for content.
Why the other options are wrong
- B. While a good starting point, generic modules may not address the organization's unique and most critical risks.
- C. Regulatory requirements dictate that training happens, but not necessarily what specific content is most effective for the organization's unique risks.
- D. Employee preferences are important for engagement, but they don't dictate the critical content that addresses actual risks.
Risk-Based Security Awareness
An approach to security awareness and training that tailors content and delivery to address the specific, identified information security risks and past incidents relevant to the organization.
- Focuses on actual threats.
- Maximizes program effectiveness.
- Driven by risk assessments and incident data.
Memory trick: Risks Reveal Real Rationale.