ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsHard
A CISA is evaluating an organization's security awareness training program. The program consists of annual, mandatory online modules that cover general security topics for all employees. However, a recent phishing simulation revealed that employees in the finance department were disproportionately susceptible to emails impersonating senior management, leading to credential harvesting. What is the MOST effective recommendation to address this specific vulnerability?
- ADevelop and deliver role-based security awareness training for the finance department.
- BImpose stricter disciplinary actions for employees who fail phishing simulations.
- CIncrease the frequency of the general security awareness training for all employees.
- DImplement more advanced technical controls like email sandboxing.
Show answer & explanationAnswer & explanation
Correct answer: A. Develop and deliver role-based security awareness training for the finance department.
The current general training is insufficient for specific, targeted threats. Role-based training tailored to the finance department, focusing on social engineering tactics like executive impersonation and the specific risks they face, would be most effective in improving their ability to recognize and resist such attacks.
Why the other options are wrong
- B. Disciplinary actions can be demotivating and are less effective than education in building a security-aware culture.
- C. Increasing frequency of general training might help, but it won't specifically address the targeted vulnerability of the finance department.
- D. Technical controls are important, but the question focuses on improving the human element through training. This is a complementary, not primary, solution to a training gap.
Role-Based Security Awareness Training
Security awareness training customized to the specific roles, responsibilities, and threats faced by different departments or groups within an organization.
- More relevant and engaging for participants.
- Addresses specific risks associated with job functions.
- Improves the effectiveness of security awareness programs.
Memory trick: Don't teach all your players the same moves; train your goalie differently than your striker.