Following an increase in security events involving remote employees working from public locations, an organization updates its security awareness program to focus on human risk management for mobile workers. Which of the following administrative and operational security awareness controls should the security team implement to directly address these human-centric risks? (Select TWO.)
- Mandatory awareness modules covering visual eavesdropping risks and requiring privacy filter usage in public spacesCevap
- BAutomated Network Access Control (NAC) posture checks that isolate non-compliant devices before allowing network entry
- Clear reporting procedures and timelines for personnel to notify security operations upon losing a mobile deviceCevap
- DTargeted whaling simulation campaigns sent exclusively to executive staff regarding fraudulent wire transfer requests
Cevap
The organization should implement mandatory awareness modules covering visual eavesdropping and privacy filter usage, alongside clear reporting procedures for lost or stolen mobile devices.
Educating mobile workers on visual eavesdropping risks alongside mandating privacy screen usage addresses the physical human risks of working in public. Additionally, establishing explicit protocols for employees to report missing devices ensures human compliance with incident handling escalation.
Adım Adım Çözüm
Anahtar Kavram
Security Awareness Programs and Human Risk Management for Remote/Mobile Workforces
Tahmini Süre:1m 30s