A chief information security officer (CISO) observes that system administrators are frequently targeted with sophisticated social engineering tactics tailored specifically to technical environments. Which training approach is most effective for addressing this human risk?
- Role-based security training designed around the elevated privileges and specific attack vectors of technical staffAnswer
- BUniversal annual baseline awareness training covering general corporate password policies for all employees
- CImmediate disciplinary escalation and credential revocation for any administrator who falls for a phishing simulation
- DReclassifying social engineering defenses as network perimeter firewalls rather than administrative security awareness controls
Answer
Role-based security training designed around the elevated privileges and specific attack vectors of technical staff
Role-based awareness training customizes educational material to match the responsibilities, privilege levels, and specific attack vectors encountered by distinct job roles such as system administrators.
Step-by-Step Solution
Key Concept
Role-based security awareness and human risk management