ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsHard

A CISA is performing an audit of an organization's security awareness training program. The CISA reviews training materials, completion records, and survey feedback. The CISA notes that while 95% of employees complete the annual training, phishing simulation tests consistently show a click-through rate of 25%, and a significant number of help desk tickets relate to users reporting suspicious emails that are actually legitimate. What is the MOST likely root cause of these issues?

  1. AThe organization's security culture does not prioritize vigilance.
  2. BEmployees are not motivated to apply the training in practice.
  3. CThe training methods and content are ineffective in changing behavior.
  4. DThe security awareness training is too technical for the average employee.
Show answer & explanation

Correct answer: C. The training methods and content are ineffective in changing behavior.

Despite high completion rates, a high phishing click-through rate and misidentification of legitimate emails indicate that the training is not effectively translating knowledge into changed behavior. This points to deficiencies in the training's content, delivery methods, or relevance, rather than just a lack of motivation or a poor culture, which are broader concepts that training aims to address.

Why the other options are wrong

  • A. While security culture is important, ineffective training is a more direct and actionable root cause that impacts behavior, which in turn shapes culture.
  • B. Lack of motivation is a possible factor, but 'ineffective training' is a more direct cause, as effective training should foster motivation and engagement.
  • D. If it were too technical, completion rates might be lower, and employees might express confusion, which isn't specified.

Security Awareness Training Effectiveness

The degree to which security awareness training successfully changes employee behavior to reduce security risks, measured by metrics beyond just completion rates.

  • Behavioral change is the ultimate goal, not just knowledge acquisition.
  • Measured by phishing simulation results, incident rates, help desk tickets.
  • Requires engaging content, relevant examples, and continuous reinforcement.

Memory trick: Learning the words doesn't mean you'll sing the song right; the lesson itself is off-key.

More Domain 5: Protection of Information Assets questions