An enterprise security administrator is formalizing a human risk management initiative to reduce departmental vulnerability to targeted social engineering attacks. In what order should the administrator execute the stages of this security awareness lifecycle from start to finish?
- 1Conduct a baseline human risk assessment to identify high-vulnerability job roles and specific threat vectors.
- 2Develop tailored, role-based microlearning content that directly addresses the identified threat vectors.
- 3Deliver targeted security training to high-risk personnel and track initial completion metrics.
- 4Execute unannounced simulated phishing campaigns to evaluate behavioral change and user reporting rates.
- 5Present aggregated risk reduction metrics to leadership and refine the enterprise security awareness policy.
Cevap
The correct sequence begins with conducting a baseline human risk assessment, followed by developing tailored role-based training modules, delivering the targeted training to key personnel, executing unannounced simulations to measure behavioral changes, and concluding with reporting risk reduction metrics to leadership to refine governance policy.
The correct sequence follows the standard security program lifecycle: first assess baseline risks to identify vulnerable roles, second develop tailored role-based learning content, third deliver training to targeted personnel, fourth evaluate behavioral change using unannounced simulations, and fifth present outcome metrics to leadership to update overall program governance.
Adım Adım Çözüm
Anahtar Kavram
Role-Based Security Awareness Program Lifecycle