A newly appointed information security manager finds that staff routinely share login credentials and bypass access controls, even though a detailed acceptable-use policy exists and is technically sound. Senior executives openly describe these controls as obstacles to getting work done. Which factor is MOST likely the root cause of the weak security behaviour?
- AThe acceptable-use policy lacks sufficient technical detail on credential management procedures.
- BThe tone at the top signals that security is a hindrance, shaping a culture in which non-compliance is normalised. Correct
- CEmployees have not yet completed the annual security awareness training module on password hygiene.
- DThe access control technology is misconfigured and permits credential sharing without detection.
Why A is wrong: Tempting because policy gaps are a common finding, but the scenario states the policy is detailed and technically sound, so additional detail would not change behaviour driven by leadership attitude.
Why B is correct: Correct because when senior leadership visibly treats controls as obstacles, employees model that attitude, and this leadership-set tone is the dominant influence on the prevailing security culture and behaviour.
Why C is wrong: Tempting because awareness gaps do drive poor habits, but training cannot overcome a culture in which leadership openly devalues controls, so the absence of training is a symptom rather than the root cause.
Why D is wrong: Tempting because technical weaknesses can enable bad behaviour, but the issue described is a deliberate choice to bypass working controls, which points to culture and leadership rather than a configuration fault.