Following a recent security audit, an enterprise identifies a surge in successful voice phishing (vishing) attacks targeting helpdesk staff to execute unauthorized multi-factor authentication (MFA) resets. Additionally, metrics indicate that end users rarely report suspicious phone calls due to a complex submission workflow and fear of disciplinary action for false alarms. Which of the following human risk management strategies should the organization implement to directly address these vulnerabilities? (Select TWO.)
- Establish role-based out-of-band identity verification protocols specifically for helpdesk personnel handling credential reset requests.Cevap
- Implement a non-punitive security reporting policy coupled with a simplified, single-click event reporting workflow.Cevap
- CIncrease the duration and completion pass threshold of annual general security awareness computer-based training modules for all staff.
- DReclassify helpdesk social engineering verification workflows as technical detective controls within the enterprise risk register.
Cevap
The organization should establish role-based out-of-band identity verification protocols for helpdesk personnel and implement a non-punitive security reporting policy with a simplified reporting workflow.
Establishing role-based out-of-band identity verification directly counters vishing attacks aimed at service desk personnel by enforcing strict operational authentication procedures. Additionally, implementing a non-punitive reporting policy with streamlined reporting channels addresses employee fear of false alarms, fostering a positive security culture that encourages immediate incident reporting.
Adım Adım Çözüm
Anahtar Kavram
Role-Based Security Training and Human Risk Mitigation