An organization's security manager is implementing a human risk management campaign to address a high frequency of unattended, unlocked workstations observed during an internal audit. In what chronological order should the security manager execute the following phases of the campaign, from initial risk assessment to program evaluation?
- 1Perform a baseline audit across department locations to record quantitative workstation locking compliance metrics.
- 2Develop role-based microlearning modules focusing on screen-locking keyboard shortcuts and clean desk policy standards.
- 3Deploy mandatory interactive training modules alongside automated group policy enforcement for screen-saver timeouts.
- 4Conduct unannounced follow-up audits to measure behavioral improvement against the initial baseline.
Cevap
The correct sequence begins with performing a baseline compliance audit, followed by developing targeted microlearning modules, executing the training alongside technical controls, and concluding with follow-up audits to evaluate behavioral improvement.
A structured security awareness and human risk management framework follows a logical progression: assessment, design, deployment, and evaluation. Conducting a baseline audit establishes pre-intervention compliance levels. Designing targeted training materials directly addresses the vulnerabilities identified in the audit. Deploying the modules and technical controls applies the remediation, and performing unannounced post-training audits provides the quantitative data necessary to evaluate program efficacy against the baseline.
Adım Adım Çözüm
Anahtar Kavram
Human Risk Mitigation Program Lifecycle
Tahmini Süre:1m 30s