712-50 · Question #18
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?
The correct answer is B. Every 12 months. Option B is correct because major security frameworks and standards - including ISO 27001, NIST SP 800-50, and PCI DSS - consistently recommend annual (every 12 months) security awareness training as the baseline best practice for all employees, regardless of risk level. Option…
Question
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?
Options
- AHigh risk environments 6 months, low risk environments 12 months
- BEvery 12 months
- CEvery 18 months
- DEvery six months
How the community answered
(61 responses)- A7% (4)
- B72% (44)
- C5% (3)
- D16% (10)
Explanation
Option B is correct because major security frameworks and standards - including ISO 27001, NIST SP 800-50, and PCI DSS - consistently recommend annual (every 12 months) security awareness training as the baseline best practice for all employees, regardless of risk level. Option A is wrong because the standards do not bifurcate training frequency by risk environment in this way - all employees receive training on the same cycle. Option C (18 months) is too infrequent and does not align with any recognized standard; the threat landscape evolves too quickly to justify that gap. Option D (six months) may seem like a "more security is better" answer, but it exceeds the standard requirement and is not mandated by best practices, making it incorrect in the context of what standards prescribe.
Memory tip: Think "annual review" - just like performance reviews happen once a year, so does security awareness training. Both keep employees accountable on a 12-month cycle.
Topics
Community Discussion
No community discussion yet for this question.