CAS-002 · Question #132
As part of the ongoing information security plan in a large software development company, the Chief Information officer (CIO) has decided to review and update the company's privacy policies and…
The correct answer is B. customized for the various departments and staff roles. Security awareness training is most effective when tailored to the specific roles and responsibilities of each department rather than delivered uniformly to all staff.
Question
As part of the ongoing information security plan in a large software development company, the Chief Information officer (CIO) has decided to review and update the company's privacy policies and procedures to reflect the changing business environment and business requirements. Training and awareness of the new policies and procedures has been incorporated into the security awareness program which should be:
Options
- Apresented by top level management to only data handling staff.
- Bcustomized for the various departments and staff roles.
- Ctechnical in nature to ensure all development staff understand the procedures.
- Dused to promote the importance of the security department.
How the community answered
(26 responses)- A8% (2)
- B88% (23)
- C4% (1)
Why each option
Security awareness training is most effective when tailored to the specific roles and responsibilities of each department rather than delivered uniformly to all staff.
Limiting training to only data handling staff ignores that all employees represent potential security risk vectors, and executive-only presentations are less effective than targeted, interactive role-based training.
Customizing training for different departments and roles ensures that each employee receives guidance relevant to their specific data handling responsibilities and threat exposure. A developer's security concerns differ significantly from those of HR or finance staff, making role-based training more effective at driving behavioral change and meaningful policy compliance.
Technical security training is appropriate only for technical roles; non-technical employees need training aligned with their own workflows and risks rather than developer-focused procedures.
Security awareness programs exist to reduce organizational risk, not to promote the security department - framing the program this way undermines its credibility and behavioral impact.
Concept tested: Role-based security awareness training program design
Source: https://csrc.nist.gov/publications/detail/sp/800-50/final
Topics
Community Discussion
No community discussion yet for this question.