ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsEasy
A CISA is auditing an organization's information security strategy. The CISA observes that while the strategy addresses technical controls and compliance requirements, it lacks specific objectives for fostering a security-conscious culture among employees. Which of the following is the MOST significant risk posed by this omission?
- ADifficulty in obtaining executive buy-in for security initiatives.
- BNon-compliance with regulatory data protection mandates.
- CIncreased susceptibility to social engineering attacks.
- DChallenges in integrating new security technologies.
Show answer & explanationAnswer & explanation
Correct answer: C. Increased susceptibility to social engineering attacks.
A lack of a security-conscious culture makes employees more vulnerable to manipulation, directly increasing the risk of social engineering attacks. Technical controls and compliance alone cannot fully mitigate human-centric threats.
Why the other options are wrong
- A. Executive buy-in is important, but a lack of culture doesn't directly cause this; it's more about demonstrating value and risk.
- B. While a security-conscious culture supports compliance, the primary and most direct risk of its absence is human vulnerability to attacks, not necessarily an immediate failure to meet mandates.
- D. While culture can influence adoption, technical integration issues are primarily technical and process-related, not a direct outcome of lacking a security-conscious culture.
Security-Conscious Culture
An organizational environment where employees prioritize and actively participate in maintaining information security through awareness, vigilance, and adherence to security policies.
- Reduces human error as a vector for attacks.
- Complements technical controls and policies.
- Fosters a proactive security posture.
Memory trick: Culture's Core: Human Shield Against Social Snares.