CGEIT · Question #205
An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?
The correct answer is A. Distribute the social media information security policy to staff.. From a governance perspective, the most effective way to mitigate social engineering risk related to human factors is to formally define acceptable behavior through a security policy.
Question
An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?
Options
- ADistribute the social media information security policy to staff.
- BMandate annual security awareness training.
- CRestrict access to social media.
- DMandate security requirements be included in employee contracts.
How the community answered
(58 responses)- A72% (42)
- B17% (10)
- C7% (4)
- D3% (2)
Why each option
From a governance perspective, the most effective way to mitigate social engineering risk related to human factors is to formally define acceptable behavior through a security policy.
Distributing a social media information security policy to staff is the BEST governance-level action because it formally establishes clear expectations and rules regarding social media usage and information sharing. This policy provides the necessary framework to guide employee behavior and defines acceptable conduct, directly addressing the human factors contributing to social engineering risks.
Mandating annual security awareness training is important for education, but without a clear formal policy, the training might lack specific actionable guidelines for social media use.
Restricting access to social media is a technical control, which might be part of a broader strategy, but it doesn't directly address the human factor of *understanding* and *adhering* to secure practices when social media is necessary or unavoidable.
Mandating security requirements in employee contracts is a legal measure for accountability, but it doesn't proactively educate or guide employees on daily secure practices regarding social media usage.
Concept tested: Mitigating social engineering via governance
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security-baseline/security-disciplines-identity
Topics
Community Discussion
No community discussion yet for this question.