CISM · Question #327
Which of the following should be the PRIMARY consideration when designing an organization's information security awareness and training program?
The correct answer is C. Security culture. Security culture (C) is the primary consideration because an awareness and training program exists to shape how people think, behave, and make decisions around security - its ultimate goal is to embed security-conscious behavior into the organization's DNA. Without targeting…
Question
Which of the following should be the PRIMARY consideration when designing an organization's information security awareness and training program?
Options
- AIndustry security trends
- BEmerging security technologies
- CSecurity culture
- DCurrent security skill sets
How the community answered
(35 responses)- A6% (2)
- B3% (1)
- C89% (31)
- D3% (1)
Explanation
Security culture (C) is the primary consideration because an awareness and training program exists to shape how people think, behave, and make decisions around security - its ultimate goal is to embed security-conscious behavior into the organization's DNA. Without targeting culture, even technically excellent training fails to change real-world behavior.
Why the distractors fall short:
- (A) Industry security trends are useful inputs for keeping content current, but they're secondary to the cultural goal the program is trying to achieve.
- (B) Emerging security technologies belong in technical training curricula, not in the foundational design of an awareness program aimed at the broader workforce.
- (D) Current security skill sets help identify gaps for training content, but assessing skills is a means to building culture, not the primary design driver.
Memory tip: Think of it this way - you can teach people what to do (skills) and show them what's new (trends/tech), but if the culture doesn't value security, none of it sticks. Culture is the container that holds everything else together.
Topics
Community Discussion
No community discussion yet for this question.