CISA - Protection of Information Assets - Section 5.2

Evaluate security awareness training and programs and information system attack methods and techniques.

Recognise the components of an effective security awareness training programme and how it reduces the risk of social engineering and human error. Distinguish common IS attack methods and techniques - such as phishing, ransomware and insider threats - and the threat actor categories associated with each.

security awareness trainingattack methodsattack techniquesthreat actors

Practice question for this objective

Free sampleProtection of Information Assetsmedium

An IS auditor is reviewing the design of a security awareness programme for a national insurer. Which characteristic BEST distinguishes a mature awareness programme from a one-off training campaign?

  • AAnnual computer-based training that all employees must complete by year-end to satisfy the regulator.
  • BContinuous reinforcement using role-tailored content, behavioural metrics, and content refreshed against the current threat landscape. Correct
  • CA signed acceptable-use policy collected from each new joiner during the onboarding induction session.
  • DA quarterly newsletter from the chief information security officer summarising recent incidents handled by the security operations centre.
Recognise that a mature security awareness programme is continuous, role-tailored, threat-driven, and measured by behavioural outcomes rather than completion rates. Awareness maturity models such as those described in NIST SP 800-50 and SANS Security Awareness Maturity Model treat awareness as a sustained behaviour-change programme. The key indicators are role tailoring, continuous reinforcement, threat-informed content updates, and quantitative behavioural metrics. Annual completion, policy signatures, or newsletters are inputs, not the programme itself, and none of them evidences behaviour change over time.

Why A is wrong: Annual mandatory training is a baseline regulatory floor and is tempting because most organisations satisfy compliance this way, but it is a point-in-time campaign rather than an ongoing programme tied to measurable behaviour change.

Why B is correct: Maturity in awareness is defined by sustained reinforcement, role-relevant content, behavioural metrics such as phishing click and report rates, and refresh cycles aligned to current threat intelligence rather than a single annual event.

Why C is wrong: Capturing a policy acknowledgement is a useful administrative control and looks like awareness, but a signature confirms receipt only and does nothing to reinforce behaviour, measure understanding, or evolve content with the threat landscape.

Why D is wrong: Executive newsletters provide visibility and are easy to confuse with reinforcement, yet a one-way bulletin neither tailors content to role-specific risk nor measures whether staff behaviour actually changes as a result.

See more CISA practice questions, answers explained.

More in this domain

Back to all Protection of Information Assets objectives, or the CISA cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.