A regional council's security manager is briefing the executive on what the council should measure to know whether its security awareness programme is actually working. The chief executive has asked for a small set of indicators that reflect changes in user behaviour over time, not just whether staff have completed mandatory training. Which set of indicators most directly meets the chief executive's request?
- AThe number of awareness modules published in the learning management system each quarter and the total length in minutes of all training content available to staff.
- BThe completion rate of the annual mandatory module and the percentage of staff who scored above a fixed pass mark on the final quiz.
- CThe phishing simulation click rate, the phishing report rate via the report-phishing button, the repeat-click rate for staff who failed previous simulations, and the volume of genuine suspicious messages reported by staff. Correct
- DThe number of new security policies published each year and the count of policy exceptions granted, broken down by department.
Why A is wrong: Content volume measures programme output, not user behaviour. A larger module catalogue is consistent with declining staff engagement and gives the executive no insight into whether behaviour is changing.
Why B is wrong: Completion and quiz scores measure attendance and short-term recall. They do not track whether staff are reporting phishing, recognising anomalies, or improving over time, which is what the chief executive specifically asked for.
Why C is correct: These four indicators directly measure user behaviour over time. Together they show whether staff are clicking less, reporting more, learning after a mistake, and applying the same reporting habit to real attacks, which is exactly what the chief executive asked for.
Why D is wrong: Policy and exception counts are governance metrics rather than awareness metrics. They tell the executive about document flow and exception management, not about how staff are behaving in their daily use of systems.