CISSP · Question #1337
What is the MOST important factor in establishing an effective Information Security Awareness Program?
The correct answer is A. Obtain management buy-in. Establishing an effective Information Security Awareness Program requires organizational support and resources, which can only be secured through management buy-in. Without executive sponsorship, the program lacks authority, funding, and enforcement mechanisms.
Question
What is the MOST important factor in establishing an effective Information Security Awareness Program?
Options
- AObtain management buy-in.
- BConduct an annual security awareness event.
- CMandate security training.
- DHang information security posters on the walls,
How the community answered
(23 responses)- A78% (18)
- B4% (1)
- C13% (3)
- D4% (1)
Why each option
Establishing an effective Information Security Awareness Program requires organizational support and resources, which can only be secured through management buy-in. Without executive sponsorship, the program lacks authority, funding, and enforcement mechanisms.
Management buy-in is the foundational requirement for any security awareness program because it provides the authority, budget, and organizational mandate needed to implement and sustain the program. Without executive support, security initiatives cannot be enforced, resourced, or integrated into company culture. Management sponsorship also signals to employees that security is a priority, dramatically increasing participation and compliance.
An annual security awareness event is insufficient on its own, as effective programs require continuous, ongoing education rather than a single yearly occurrence to address evolving threats.
While mandating security training is a useful component, it is dependent on management buy-in to be enforceable and meaningful, making it a downstream activity rather than the most critical factor.
Hanging information security posters is a passive, supplementary awareness tactic with minimal measurable impact and does not constitute a comprehensive or effective awareness program on its own.
Concept tested: Information Security Awareness Program critical success factors
Source: https://csrc.nist.gov/publications/detail/sp/800-50/final
Topics
Community Discussion
No community discussion yet for this question.