An organization's finance department frequently receives fraudulent email requests attempting to alter vendor wire transfer details. Although employees successfully complete mandatory annual security awareness training, several staff members recently processed unauthorized payment changes. Which of the following approaches represents the most effective security awareness and human risk management control to address this vulnerability?
- Deliver tailored, role-based microlearning and practical simulations enforcing out-of-band verification for payment change requests.Answer
- BRequire all corporate staff across all departments to immediately re-watch the general baseline security awareness video.
- CDeploy network access control rules to isolate accounting workstations whenever external email attachments are opened.
- DInstitute mandatory voice phishing (vishing) simulations focused exclusively on IT helpdesk password reset workflows.
Answer
Deliver tailored, role-based microlearning and practical simulations enforcing out-of-band verification for payment change requests.
Role-based training combined with targeted simulations provides specialized employees with relevant procedural defenses—such as verifying wire transfers using out-of-band communication—which effectively reduces human risk in high-exposure departments.
Step-by-Step Solution
Key Concept
Role-Based Security Awareness and Human Risk Mitigation