An IS auditor is reviewing the design of a security awareness programme for a national insurer. Which characteristic BEST distinguishes a mature awareness programme from a one-off training campaign?
- AAnnual computer-based training that all employees must complete by year-end to satisfy the regulator.
- BContinuous reinforcement using role-tailored content, behavioural metrics, and content refreshed against the current threat landscape. Correct
- CA signed acceptable-use policy collected from each new joiner during the onboarding induction session.
- DA quarterly newsletter from the chief information security officer summarising recent incidents handled by the security operations centre.
Why A is wrong: Annual mandatory training is a baseline regulatory floor and is tempting because most organisations satisfy compliance this way, but it is a point-in-time campaign rather than an ongoing programme tied to measurable behaviour change.
Why B is correct: Maturity in awareness is defined by sustained reinforcement, role-relevant content, behavioural metrics such as phishing click and report rates, and refresh cycles aligned to current threat intelligence rather than a single annual event.
Why C is wrong: Capturing a policy acknowledgement is a useful administrative control and looks like awareness, but a signature confirms receipt only and does nothing to reinforce behaviour, measure understanding, or evolve content with the threat landscape.
Why D is wrong: Executive newsletters provide visibility and are easy to confuse with reinforcement, yet a one-way bulletin neither tailors content to role-specific risk nor measures whether staff behaviour actually changes as a result.