nerdexam
Isaca

CGEIT · Question #205

An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?

The correct answer is A. Distribute the social media information security policy to staff.. From a governance perspective, the most effective way to mitigate social engineering risk related to human factors is to formally define acceptable behavior through a security policy.

Submitted by eva_at· Apr 18, 2026Risk Optimization

Question

An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?

Options

  • ADistribute the social media information security policy to staff.
  • BMandate annual security awareness training.
  • CRestrict access to social media.
  • DMandate security requirements be included in employee contracts.

How the community answered

(58 responses)
  • A
    72% (42)
  • B
    17% (10)
  • C
    7% (4)
  • D
    3% (2)

Why each option

From a governance perspective, the most effective way to mitigate social engineering risk related to human factors is to formally define acceptable behavior through a security policy.

ADistribute the social media information security policy to staff.Correct

Distributing a social media information security policy to staff is the BEST governance-level action because it formally establishes clear expectations and rules regarding social media usage and information sharing. This policy provides the necessary framework to guide employee behavior and defines acceptable conduct, directly addressing the human factors contributing to social engineering risks.

BMandate annual security awareness training.

Mandating annual security awareness training is important for education, but without a clear formal policy, the training might lack specific actionable guidelines for social media use.

CRestrict access to social media.

Restricting access to social media is a technical control, which might be part of a broader strategy, but it doesn't directly address the human factor of *understanding* and *adhering* to secure practices when social media is necessary or unavoidable.

DMandate security requirements be included in employee contracts.

Mandating security requirements in employee contracts is a legal measure for accountability, but it doesn't proactively educate or guide employees on daily secure practices regarding social media usage.

Concept tested: Mitigating social engineering via governance

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security-baseline/security-disciplines-identity

Topics

#Social Engineering Risk#Policy Management#Risk Mitigation#IT Governance

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice