Question

Difficulty: MediumSecurity Awareness Programs and Human Risk Management

A chief information security officer (CISO) is shifting the organization's security awareness program from measuring basic compliance attendance to evaluating quantifiable human risk reduction. Which of the following metrics or strategies effectively measure behavioral change and operational human risk mitigation? (Select TWO.)

  1. Tracking trends in employee suspicious email reporting rates alongside click-through rates during periodic simulated phishing campaignsAnswer
  2. Monitoring the volume of user-submitted security alerts verified as genuine threats by the security operations centerAnswer
  3. C
    Deploying automated inline perimeter firewall rules to drop incoming email messages containing compressed file attachments
  4. D
    Requiring all workforce members to re-certify annually by completing a static slide-based regulatory compliance module

Answer

The effective methods for measuring behavioral change and operational human risk reduction are tracking trends in employee reporting rates versus click-through rates during simulated phishing campaigns, and monitoring the volume of user-submitted security alerts verified as genuine threats by the security operations center.
Tracking simulated phishing reporting and click-through trends provides empirical data on employee susceptibility and reporting habits. Similarly, tracking verified threat submissions demonstrates that employees are actively applying awareness training to defend the enterprise, providing clear indicators of human risk reduction.

Step-by-Step Solution

1
Identify the primary objective of human risk management evaluation
Recognize that human risk metrics must evaluate observable user behaviors and threat detection capabilities rather than technical controls or simple course attendance.
Security awareness programs aim to foster security-conscious behavior across the workforce.
2
Evaluate behavioral measurement strategies
Simulated phishing metrics (reporting vs. clicking) and verified user incident submissions directly quantify how effectively employees recognize and report threats.
These metrics reflect active human threat detection and resistance to social engineering.
3
Differentiate technical controls and compliance tracking from behavioral metrics
Eliminate options focusing on technical filtering controls or passive annual training completion tracking.
Technical controls operate independently of user behavior, and compliance completion only proves attendance, not risk reduction.

Key Concept

Security Awareness Program Metrics and Human Risk Management
Rate this question