An enterprise security operations team observes that standard annual security awareness lectures have been ineffective at stopping employees from uploading sensitive company documents to unapproved personal cloud storage services. To enhance their human risk management framework, the security team seeks to implement an operational solution that delivers immediate, context-aware microlearning prompts at the exact moment a risky file-transfer action is attempted. Which of the following approaches best meets this objective?
- Implement just-in-time (JIT) training triggers integrated with Data Loss Prevention (DLP) policy promptsCevap
- BSchedule mandatory quarterly spear-phishing simulation campaigns for all staff
- CDeploy a strict perimeter firewall rule that silently drops unapproved web connection requests
- DRequire all policy violators to retake the full length annual security compliance video course
Cevap
Implementing just-in-time (JIT) training triggers integrated with Data Loss Prevention (DLP) policy prompts is the most effective approach.
Just-in-time (JIT) security awareness training integrated with Data Loss Prevention (DLP) pop-up alerts intercept risky user actions (such as uploading sensitive data to personal cloud services) in real time. Providing immediate, contextual microlearning prompts at the moment of violation helps employees understand the risk and policy rule instantly, driving long-term behavioral modification.
Adım Adım Çözüm
Anahtar Kavram
Just-in-Time (JIT) Security Awareness and Contextual Microlearning