CISM - Information Security Program - Section 3.9

Develop and manage an information security awareness and training programme for all personnel.

Develop and manage a security awareness training programme that covers all personnel and uses techniques such as phishing simulation to reinforce learning. Measure the programme's impact on behaviour and use results to drive culture change and continuous improvement.

Security awarenessTraining programmePhishing simulationCulture change

Practice question for this objective

Free sampleInformation Security Programeasy

An information security manager introduces periodic simulated phishing exercises as part of the awareness programme. A staff representative asks what the simulations are primarily intended to achieve. What is the main purpose of running phishing simulations?

  • ATo measure how staff respond to realistic lures and reinforce safe behaviour through timely, targeted follow-up training. Correct
  • BTo generate disciplinary evidence so that employees who repeatedly fail the simulations can be formally sanctioned by management.
  • CTo satisfy the auditors that a phishing control exists, allowing the manager to mark the awareness requirement as complete for the year.
  • DTo test whether the email gateway and spam filtering technology can detect and quarantine the simulated phishing messages reliably.
Phishing simulations exist to measure human susceptibility and reinforce safe behaviour through follow-up training, not to punish staff or test technical filters. Simulated phishing surfaces how people respond to realistic lures and provides a teachable moment to correct unsafe behaviour, which advances the behavioural objective of awareness rather than serving as a disciplinary or technical-control mechanism.

Why A is correct: Correct because simulations reveal real susceptibility and create a teachable moment, letting the manager reinforce safe behaviour where it is weakest, which is the behavioural aim of awareness.

Why B is wrong: Using simulations to punish staff is tempting as an accountability lever, but a punitive aim discourages reporting and erodes trust, which works against the programme's behavioural goal.

Why C is wrong: Treating simulations as a compliance tick is tempting because it closes an audit finding, but running them only for evidence ignores their real value in changing how staff respond.

Why D is wrong: Testing the mail gateway is tempting because the simulation uses email, but that is a technical control test, whereas phishing simulations exist to assess and improve human behaviour.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Program objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.