ExamGecko
Question list
Search
Search

Related questions

Question 998 - CISA discussion

Report
Export

Which of the following is MOST important to ensure when developing an effective security awareness program?

A.
Training personnel are information security professionals.
Answers
A.
Training personnel are information security professionals.
B.
Outcome metrics for the program are established.
Answers
B.
Outcome metrics for the program are established.
C.
Security threat scenarios are included in the program content.
Answers
C.
Security threat scenarios are included in the program content.
D.
Phishing exercises are conducted post-training
Answers
D.
Phishing exercises are conducted post-training
Suggested answer: B

Explanation:

The most important factor to ensure when developing an effective security awareness program is B. Outcome metrics for the program are established.This is because outcome metrics are measures that evaluate the impact and results of the security awareness program on the behavior and performance of the users, and the security posture and objectives of the organization1. Outcome metrics can help ensure the effectiveness of the security awareness program by:

Providing feedback and evidence on whether the security awareness program is achieving its goals and expectations, such as reducing the number of incidents, improving the compliance rate, or increasing the reporting rate1.

Identifying and quantifying the strengths and weaknesses of the security awareness program, and enabling continuous improvement and optimization of the program content, delivery, and frequency1.

Demonstrating and communicating the value and return on investment of the security awareness program to the stakeholders and management, and securing their support and commitment for the program1.

asked 18/09/2024
Donald VIRMOND
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first