A healthcare organization recently modified its human risk management framework after evaluating performance metrics across high-risk departments during simulated phishing campaigns. The IT operations team achieved a low phishing click-through rate of , but their mean time to report (MTTR) credential-harvesting simulations was 18 hours. Conversely, the medical billing department registered an click-through rate, yet of received phishing simulations were reported to the Security Operations Center (SOC) within 15 minutes of delivery. To accurately calibrate the organization's human risk posture and implement targeted security awareness interventions, which of the following actions represents the most effective security program strategy?
- Develop a composite Human Risk Score (HRS) incorporating reporting velocity and incident amplification metrics alongside click-through rates, while deploying specialized microlearning on timely incident escalation for IT operations.Cevap
- BReconfigure the Secure Email Gateway (SEG) to automatically drop all external emails containing embedded hyperlinks sent to the IT operations department.
- CMandate an annual multi-hour security awareness lecture focused on identifying vishing and smishing tactics for the medical billing department.
- DDeploy hardware token multi-factor authentication (MFA) to act as a deterrent control that discourages medical billing employees from clicking suspicious phishing links.
Cevap
Develop a composite Human Risk Score (HRS) incorporating reporting velocity and incident amplification metrics alongside click-through rates, while deploying specialized microlearning on timely incident escalation for IT operations.
The correct strategy establishes a comprehensive Human Risk Score (HRS) that incorporates both reporting speed and click-through rates. In human risk management, rapid reporting by end users turns the workforce into a distributed detection network, significantly reducing threat dwell time. Because IT operations delayed reporting for 18 hours, targeted microlearning on escalation pathways directly resolves the critical behavioral risk identified in the metrics.
Adım Adım Çözüm
Anahtar Kavram
Human Risk Metrics and Role-Based Security Awareness Calibration