ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium
An organization's security policy states that all employees must complete security awareness training annually. However, a recent audit revealed that only 60% of employees completed the training last year. Furthermore, the training content has not been updated in three years, despite significant changes in the threat landscape. This situation indicates a weakness in which aspect of the security awareness, training, and education (SATE) program?
- AContent relevance and currency
- BProgram evaluation and enforcement
- CDelivery mechanism effectiveness
- DInitial awareness campaign design
Show answer & explanationAnswer & explanation
Correct answer: B. Program evaluation and enforcement
The scenario highlights two key issues: low completion rates (lack of enforcement/tracking) and outdated content (lack of evaluation/update). Both point to a deficiency in the ongoing management and oversight of the SATE program, specifically its evaluation and enforcement mechanisms.
Why the other options are wrong
- A. While content currency is an issue, the lack of completion points to more than just content relevance.
- C. The delivery mechanism isn't explicitly stated as the problem; the issue is completion and content.
- D. Initial design might be fine; the problem is with ongoing management and updates.
SATE Program Evaluation
The systematic process of assessing the effectiveness and efficiency of security awareness, training, and education initiatives.
- Ensures programs meet their objectives and remain relevant.
- Involves tracking participation, testing comprehension, and reviewing content.
- Crucial for demonstrating due diligence and improving security posture.
Memory trick: Awareness is broad, Training is skills, Education is deep, and Evaluation keeps it all sharp.