Question

Difficulty: MediumSecurity Awareness Programs and Human Risk Management

An organization's security metrics reveal that high-risk departments, such as finance and human resources, continue to exhibit elevated click-through rates on sophisticated spear-phishing simulations despite completing the mandatory annual security awareness course. The CISO wants to update the awareness program to effectively reduce human risk in these departments while maintaining a supportive security culture. Which of the following strategies is the most effective approach to achieve this objective?

  1. A
    Mandate generic quarterly security training courses for the entire enterprise to ensure uniform compliance across all departments.
  2. Deliver tailored, role-based micro-learning and targeted phishing simulations designed specifically for high-risk job functions.Answer
  3. C
    Enforce immediate account suspension and mandatory HR escalation whenever an employee clicks any simulated link.
  4. D
    Implement network-level web filtering to restrict all external email access exclusively for non-technical staff.

Answer

Deliver tailored, role-based micro-learning and targeted phishing simulations designed specifically for high-risk job functions.
Role-based security awareness tailors educational content and simulated phishing scenarios to the specific threats, data access levels, and workflows of vulnerable job functions (such as financial wire transfers or HR credential targeting). Providing frequent micro-learning modules keeps threat awareness top of mind without causing training fatigue, fostering a constructive security culture.

Step-by-Step Solution

1
Analyze the organizational problem
High-risk departments (Finance, HR) face specialized threats like business email compromise and spear phishing that general awareness courses do not adequately address.
Generic baseline training provides broad compliance coverage but lacks role-specific context.
2
Evaluate human risk management controls against organizational goals
Targeted, role-based micro-learning combined with relevant simulations directly addresses function-specific threat vectors while reinforcing behavioral change.
Training must fit the user's operational context and avoid punitive policies to encourage prompt incident reporting.

Key Concept

Role-Based Security Awareness and Human Risk Management
Rate this question