An organization is updating its human risk management policy following a simulated phishing exercise that revealed widespread vulnerability among high-privilege users. To establish an effective, iterative Security Awareness and Human Risk Management cycle, in what sequential order should the security team implement the following stages?
- 1Identify high-risk user groups and evaluate baseline behavioral metrics from simulated campaigns and incident reports.
- 2Develop targeted, role-based micro-learning modules focused on specific threat vectors identified during assessment.
- 3Deploy contextual training interventions and conduct follow-up targeted phishing simulations.
- 4Analyze post-training reporting rates and adjust security awareness control policies based on residual risk metrics.
Answer
The correct sequence begins with identifying high-risk groups and baseline risk metrics, followed by developing targeted role-based training content, executing contextual interventions and simulations, and concluding with continuous feedback analysis and policy adjustments.
An effective human risk management program follows a continuous administrative lifecycle: baseline assessment and target identification must come first, followed by role-based curriculum development, practical training delivery with simulations, and final feedback analysis to drive continuous policy refinement.
Step-by-Step Solution
Key Concept
Human Risk Management Lifecycle and Security Awareness Program Design