CISM - Information Security Program (33% of the exam) - Section 3.9

Develop and manage an information security awareness and training programme for all personnel.

Develop and manage a security awareness training programme that covers all personnel and uses techniques such as phishing simulation to reinforce learning. Measure the programme's impact on behaviour and use results to drive culture change and continuous improvement.

Security awarenessTraining programmePhishing simulationCulture change

Practice question for this objective

Free sampleInformation Security Programeasy

An information security manager introduces periodic simulated phishing exercises as part of the awareness programme. A staff representative asks what the simulations are primarily intended to achieve. What is the main purpose of running phishing simulations?

  • ATo measure how staff respond to realistic lures and reinforce safe behaviour through timely, targeted follow-up training. Correct
  • BTo generate disciplinary evidence so that employees who repeatedly fail the simulations can be formally sanctioned by management.
  • CTo satisfy the auditors that a phishing control exists, allowing the manager to mark the awareness requirement as complete for the year.
  • DTo test whether the email gateway and spam filtering technology can detect and quarantine the simulated phishing messages reliably.
Phishing simulations exist to measure human susceptibility and reinforce safe behaviour through follow-up training, not to punish staff or test technical filters. Simulated phishing surfaces how people respond to realistic lures and provides a teachable moment to correct unsafe behaviour, which advances the behavioural objective of awareness rather than serving as a disciplinary or technical-control mechanism.

Why A is correct: Correct because simulations reveal real susceptibility and create a teachable moment, letting the manager reinforce safe behaviour where it is weakest, which is the behavioural aim of awareness.

Why B is wrong: Using simulations to punish staff is tempting as an accountability lever, but a punitive aim discourages reporting and erodes trust, which works against the programme's behavioural goal.

Why C is wrong: Treating simulations as a compliance tick is tempting because it closes an audit finding, but running them only for evidence ignores their real value in changing how staff respond.

Why D is wrong: Testing the mail gateway is tempting because the simulation uses email, but that is a technical control test, whereas phishing simulations exist to assess and improve human behaviour.

See more CISM practice questions, answers explained.

Exam traps in Information Security Program

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • The proportion of staff who completed the mandatory course and passed the end-of-module knowledge quiz before the deadline.

    Why it is wrong: Completion and quiz scores are tempting because they are easy to collect, but they measure participation and recall, not whether behaviour in the workplace has actually improved.

  • Deliver one standard course to every employee so the message and the assessment scores stay consistent across the whole organisation.

    Why it is wrong: A single course is tempting because it is cheap and easy to report on, but uniform content ignores that each role faces different threats, so it leaves the highest-risk behaviours unaddressed.

  • Issue formal disciplinary warnings to every employee who clicked the simulated link.

    Why it is wrong: Tempting because consequences seem to drive vigilance, but punishing participants in a simulation discourages reporting and undermines the trust a healthy security culture depends on.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.