CRISC · Question #339
Which of the following is the MOST effective way to validate organizational awareness of cybersecurity risk?
The correct answer is C. Implementing mock phishing exercises. Implementing mock phishing exercises is the most effective way to validate organizational awareness of cybersecurity risk.
Question
Which of the following is the MOST effective way to validate organizational awareness of cybersecurity risk?
Options
- AConducting security awareness training
- BUpdating the information security policy
- CImplementing mock phishing exercises
- DRequiring two-factor authentication
How the community answered
(24 responses)- A13% (3)
- B21% (5)
- C58% (14)
- D8% (2)
Why each option
Implementing mock phishing exercises is the most effective way to validate organizational awareness of cybersecurity risk.
Conducting security awareness training is crucial for *imparting* knowledge, but it doesn't *validate* whether that knowledge has been retained and translated into appropriate behavior.
Updating the information security policy defines organizational expectations but does not measure whether employees are aware of or adhering to those expectations in practice.
Mock phishing exercises provide a practical, hands-on method to assess whether employees can recognize and correctly respond to common cyber threats in a controlled, simulated environment. This approach directly measures the effectiveness of security awareness training by observing actual behavior, identifying specific gaps in awareness, and allowing for targeted remediation and reinforcement.
Requiring two-factor authentication is a technical control to enhance security, not a method to *validate* the level of organizational awareness of cybersecurity risks.
Concept tested: Cybersecurity awareness validation
Source: https://csrc.nist.gov/publications/detail/sp/800-50/rev-1/archive/2003-08-11
Topics
Community Discussion
No community discussion yet for this question.