Question

Difficulty: MediumSecurity Awareness Programs and Human Risk Management

An enterprise security administrator is formalizing a human risk management initiative to reduce departmental vulnerability to targeted social engineering attacks. In what order should the administrator execute the stages of this security awareness lifecycle from start to finish?

  1. 1Conduct a baseline human risk assessment to identify high-vulnerability job roles and specific threat vectors.
  2. 2Develop tailored, role-based microlearning content that directly addresses the identified threat vectors.
  3. 3Deliver targeted security training to high-risk personnel and track initial completion metrics.
  4. 4Execute unannounced simulated phishing campaigns to evaluate behavioral change and user reporting rates.
  5. 5Present aggregated risk reduction metrics to leadership and refine the enterprise security awareness policy.

Answer

The correct sequence begins with conducting a baseline human risk assessment, followed by developing tailored role-based training modules, delivering the targeted training to key personnel, executing unannounced simulations to measure behavioral changes, and concluding with reporting risk reduction metrics to leadership to refine governance policy.
The correct sequence follows the standard security program lifecycle: first assess baseline risks to identify vulnerable roles, second develop tailored role-based learning content, third deliver training to targeted personnel, fourth evaluate behavioral change using unannounced simulations, and fifth present outcome metrics to leadership to update overall program governance.

Step-by-Step Solution

1
Conduct a baseline risk assessment across departments.
Identifies specific threat vectors and vulnerable job roles.
Security awareness programs must be data-driven and targeted toward actual risk profiles.
2
Develop role-based microlearning modules.
Creates targeted educational content tailored to specific job responsibilities.
Tailored training addresses unique attack surfaces more effectively than generic, one-size-fits-all awareness modules.
3
Roll out training and monitor completion metrics.
Ensures targeted personnel acquire necessary threat identification skills.
Formal training must precede practical evaluation so employees know how to recognize and report threats.
4
Launch unannounced simulated attack scenarios.
Gathers empirical data on click-through rates and threat reporting performance.
Simulations test whether educational concepts successfully translate into practical behavioral defense in real-world scenarios.
5
Aggregate metrics for executive reporting and policy refinement.
Demonstrates program effectiveness and informs ongoing security governance updates.
Continuous security program management requires leadership visibility and continuous policy alignment based on measured metrics.

Key Concept

Role-Based Security Awareness Program Lifecycle
Rate this question