nerdexam
Isaca

CISM · Question #284

Which of the following is the MOST effective approach to communicate general information security responsibilities across an organization?

The correct answer is D. Provide regular security awareness training. Regular security awareness training (D) is the most effective approach because it actively communicates responsibilities through ongoing engagement, reinforces concepts over time, and reaches all staff in a consistent, measurable way - directly addressing the goal of communicatin

Submitted by khalil_dz· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is the MOST effective approach to communicate general information security responsibilities across an organization?

Options

  • ARequire staff to sign confidentiality agreements
  • BDevelop a RACI matrix for me organization
  • CPublish the information security policy on the corporate intranet
  • DProvide regular security awareness training

How the community answered

(22 responses)
  • B
    5% (1)
  • C
    5% (1)
  • D
    91% (20)

Explanation

Regular security awareness training (D) is the most effective approach because it actively communicates responsibilities through ongoing engagement, reinforces concepts over time, and reaches all staff in a consistent, measurable way - directly addressing the goal of communicating responsibilities across the organization.

Why the distractors fall short:

  • A (Confidentiality agreements): These establish legal obligations but don't educate staff on what those responsibilities actually are or how to fulfill them.
  • B (RACI matrix): A RACI defines who is responsible for specific tasks - it's a management/governance tool, not a communication mechanism for general staff awareness.
  • C (Intranet policy publication): Making a policy available is passive; there's no guarantee staff will read, understand, or retain it. Availability ≠ communication.

Memory tip: Think of the word COMMUNICATE - it implies a two-way, active process. Training is the only option that actively delivers, tests comprehension, and reinforces information. Whenever a question asks about communicating security responsibilities to all staff, training beats documentation every time.

Topics

#Security Awareness#Security Training#Communication#Organizational Responsibilities

Community Discussion

No community discussion yet for this question.

Full CISM Practice