712-50 · Question #425
Who should be involved in the development of an internal campaign to address email phishing?
The correct answer is B. Business Unite Leaders, CISO, CIO and CEO. Option B is correct because an effective internal phishing campaign requires cross-functional leadership spanning both technical and organizational authority. The CISO owns the security strategy and technical content, Business Unit Leaders ensure the message reaches employees…
Question
Who should be involved in the development of an internal campaign to address email phishing?
Options
- ABusiness unit leaders, CIO, CEO
- BBusiness Unite Leaders, CISO, CIO and CEO
- CAll employees
- DCFO, CEO, CIO
How the community answered
(58 responses)- A3% (2)
- B72% (42)
- C9% (5)
- D16% (9)
Explanation
Option B is correct because an effective internal phishing campaign requires cross-functional leadership spanning both technical and organizational authority. The CISO owns the security strategy and technical content, Business Unit Leaders ensure the message reaches employees in context-relevant ways, and the CIO/CEO provide organizational credibility and enforcement weight - without executive sponsorship, security campaigns are easily ignored.
Why the distractors fail:
- A omits the CISO, who is the most critical stakeholder for a security-specific initiative - CEO and CIO alone lack the domain expertise to shape the campaign's substance.
- C (all employees) confuses the audience of the campaign with its developers - employees are the target, not the architects.
- D replaces the CISO with the CFO, who has no direct role in security operations or policy; the CFO's concern is financial risk, not campaign design.
Memory tip: Think "BCIC" - Business units, CISO, and the C-suite (CIO/CEO). The CISO is the non-negotiable anchor for any security initiative - if you see an option without the CISO for a security campaign question, eliminate it immediately.
Topics
Community Discussion
No community discussion yet for this question.