nerdexam
Isaca

CISM · Question #21

Which of the following is MOST important for building a robust information security culture within an organization?

The correct answer is A. Mature information security awareness training across the organization. A robust information security culture is primarily built through comprehensive and mature security awareness training that educates all employees on their roles and responsibilities in maintaining security.

Submitted by tunde_lagos· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is MOST important for building a robust information security culture within an organization?

Options

  • AMature information security awareness training across the organization
  • BSecurity controls embedded within the development and operation of the IT environment
  • CSenior management approval of information security policies
  • DStrict enforcement of employee compliance with organizational security policies

How the community answered

(19 responses)
  • A
    68% (13)
  • B
    5% (1)
  • C
    11% (2)
  • D
    16% (3)

Why each option

A robust information security culture is primarily built through comprehensive and mature security awareness training that educates all employees on their roles and responsibilities in maintaining security.

AMature information security awareness training across the organizationCorrect

Mature information security awareness training is crucial because it directly educates employees on security policies, threats, and best practices, empowering them to make secure decisions and integrating security into their daily activities, which forms the bedrock of a robust security culture. This ongoing education helps transform security from a compliance task into a shared organizational value.

BSecurity controls embedded within the development and operation of the IT environment

While important for technical security, embedding security controls doesn't inherently build a culture; it's more about technical implementation than human behavior and awareness.

CSenior management approval of information security policies

Senior management approval is necessary for policy legitimacy but doesn't, by itself, translate into active employee engagement or a pervasive security culture.

DStrict enforcement of employee compliance with organizational security policies

Strict enforcement alone can lead to resentment and workarounds rather than genuine cultural adoption if not paired with understanding and education.

Concept tested: Information security culture development

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/security-awareness-training?view=o365-worldwide

Topics

#Security culture#Awareness training#Human factors#Organizational behavior

Community Discussion

No community discussion yet for this question.

Full CISM Practice