Soru

Zorluk: KolaySecurity Awareness Programs and Human Risk Management

An organization recently launched simulated phishing exercises to evaluate its human risk management program. Rather than relying solely on training completion rates, the security team wants to assess active employee engagement during a simulated attack. Which of the following metrics best indicates a positive security awareness outcome?

  1. An increase in the percentage of employees who report simulated phishing emails using the reporting toolCevap
  2. B
    An increase in the number of automated network firewall rules deployed to block external IP addresses
  3. C
    An increase in employee ability to distinguish technical differences between vishing and smishing attack vectors
  4. D
    An increase in the installation rate of endpoint antimalware agents across corporate desktop systems

Cevap

An increase in the percentage of employees who report simulated phishing emails using the reporting tool
High reporting rates of simulated phishing emails indicate that users recognize social engineering indicators and know how to report suspicious activity promptly, directly mitigating human risk.

Adım Adım Çözüm

1
Identify the primary objective of measuring human risk management in security awareness programs.
Effective security awareness metrics evaluate positive behavioral changes, such as threat recognition and rapid reporting.
Tracking user reporting behavior measures active security participation during simulated phishing attacks.
2
Differentiate human behavioral metrics from technical security controls.
Promptly reporting suspicious emails via an automated button directly proves employee vigilance.
Technical controls like firewalls or antivirus software operate independently of end-user security awareness.

Anahtar Kavram

Security Awareness Program Metrics and Phishing Reporting
Tahmini Süre:1m 0s
Bu soruyu puanla