A chief information security officer (CISO) is shifting the organization's security awareness program from measuring basic compliance attendance to evaluating quantifiable human risk reduction. Which of the following metrics or strategies effectively measure behavioral change and operational human risk mitigation? (Select TWO.)
- Tracking trends in employee suspicious email reporting rates alongside click-through rates during periodic simulated phishing campaignsAnswer
- Monitoring the volume of user-submitted security alerts verified as genuine threats by the security operations centerAnswer
- CDeploying automated inline perimeter firewall rules to drop incoming email messages containing compressed file attachments
- DRequiring all workforce members to re-certify annually by completing a static slide-based regulatory compliance module
Answer
The effective methods for measuring behavioral change and operational human risk reduction are tracking trends in employee reporting rates versus click-through rates during simulated phishing campaigns, and monitoring the volume of user-submitted security alerts verified as genuine threats by the security operations center.
Tracking simulated phishing reporting and click-through trends provides empirical data on employee susceptibility and reporting habits. Similarly, tracking verified threat submissions demonstrates that employees are actively applying awareness training to defend the enterprise, providing clear indicators of human risk reduction.
Step-by-Step Solution
Key Concept
Security Awareness Program Metrics and Human Risk Management