ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium

An organization's security policy states that all employees must complete security awareness training annually. However, a recent audit revealed that only 60% of employees completed the training last year. Furthermore, the training content has not been updated in three years, despite significant changes in the threat landscape. This situation indicates a weakness in which aspect of the security awareness, training, and education (SATE) program?

  1. AContent relevance and currency
  2. BProgram evaluation and enforcement
  3. CDelivery mechanism effectiveness
  4. DInitial awareness campaign design
Show answer & explanation

Correct answer: B. Program evaluation and enforcement

The scenario highlights two key issues: low completion rates (lack of enforcement/tracking) and outdated content (lack of evaluation/update). Both point to a deficiency in the ongoing management and oversight of the SATE program, specifically its evaluation and enforcement mechanisms.

Why the other options are wrong

  • A. While content currency is an issue, the lack of completion points to more than just content relevance.
  • C. The delivery mechanism isn't explicitly stated as the problem; the issue is completion and content.
  • D. Initial design might be fine; the problem is with ongoing management and updates.

SATE Program Evaluation

The systematic process of assessing the effectiveness and efficiency of security awareness, training, and education initiatives.

  • Ensures programs meet their objectives and remain relevant.
  • Involves tracking participation, testing comprehension, and reviewing content.
  • Crucial for demonstrating due diligence and improving security posture.

Memory trick: Awareness is broad, Training is skills, Education is deep, and Evaluation keeps it all sharp.

More Security and Risk Management questions