SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationHard

A security manager is evaluating various metrics to assess the effectiveness of the organization's security awareness program. Which of the following metrics would provide the MOST direct evidence of improved employee behavior regarding phishing attempts?

  1. AReduction in clicks on simulated phishing emails over time.
  2. BNumber of new security policies published annually.
  3. CNumber of employees completing annual security awareness training.
  4. DResults from employee satisfaction surveys about the training.
Show answer & explanation

Correct answer: A. Reduction in clicks on simulated phishing emails over time.

A reduction in clicks on simulated phishing emails directly measures a change in employee behavior in response to a specific threat (phishing). This is the most direct and actionable metric for assessing the effectiveness of training related to phishing awareness.

Why the other options are wrong

  • B. New policies indicate management action but not employee behavioral change.
  • C. Completion rates indicate participation but not necessarily improved behavior or understanding.
  • D. Satisfaction surveys measure perception, not actual security behavior or effectiveness of training in preventing incidents.

Security Awareness Program Metrics

Quantifiable measures used to evaluate the effectiveness of security awareness training programs, focusing on changes in employee knowledge, attitudes, and behaviors related to cybersecurity.

  • Should measure behavioral change.
  • Examples: phishing click rates, incident reporting rates.
  • Tracked over time to show trends.
  • Helps justify program investment.

Memory trick: Behavioral change is the true test of learning.

More Security Operations and Administration questions