CRISC - Information Technology and Security (20% of the exam) - Section 4.7

Deliver information security awareness training that changes risk-relevant behaviour.

Design and deliver information security awareness training that achieves measurable behaviour change rather than mere compliance tick-box completion. Use techniques such as phishing simulation to test and reinforce awareness, and track improvements in risk-relevant behaviour over time.

Security awarenessTrainingPhishing simulationBehaviour change

Practice question for this objective

Free sampleInformation Technology and Securityeasy

A risk practitioner is asked to show whether the annual security awareness programme is actually reducing risk-relevant behaviour. Leadership currently sees only the percentage of staff who finished the online course. Which measure would best demonstrate that the training is changing behaviour rather than merely being completed or remembered?

  • AThe proportion of staff who opened and read the full course content within the completion deadline that the learning management system enforces each year
  • BThe average score employees achieve on the end-of-module knowledge quiz that the awareness platform delivers immediately after each annual course
  • CThe total count of awareness sessions delivered and the number of staff registered for them across every business unit during the reporting period
  • DThe change over time in the rate at which staff click simulated phishing links and the rate at which they report those suspicious messages to security Correct
Recognise that observed behaviour metrics, not completion, reading or quiz scores, show whether awareness training changes risk-relevant behaviour. Completion, reading logs and quiz scores measure exposure and short-term recall, whereas simulated phishing click and report trends observe real choices under realistic conditions, so a movement in those rates is the evidence the programme is changing behaviour rather than merely being consumed.

Why A is wrong: Reading logs feel deeper than a pass mark, so they tempt as proof of engagement, but they still record consumption of content rather than any change in how staff behave once back at work.

Why B is wrong: Quiz scores look like a solid outcome and are easy to collect, yet they capture recall at the moment of testing, not whether staff apply that knowledge when a real suspicious message arrives.

Why C is wrong: Counting sessions delivered and staff registered is plausible activity reporting, but these are input and reach figures that say nothing about whether risk-relevant behaviour actually changed.

Why D is correct: Click and report rates from phishing simulations observe what staff actually do when tested, so a falling click rate alongside a rising report rate is direct evidence that behaviour has shifted.

See more CRISC practice questions, answers explained.

Exam traps in Information Technology and Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Deliver one identical annual session to every employee, since a single consistent message avoids confusion and ensures fairness across all teams

    Why it is wrong: A single uniform session is tempting for its simplicity and consistency, but generic content rarely maps to the specific risks a role faces, so it engages people weakly and fades quickly.

  • The visual production quality of the training videos, because polished and professional materials hold attention and make staff take the security messages far more seriously

    Why it is wrong: Polished material can improve engagement, but slick videos cannot overcome the example set when leaders are seen breaking the very rules the training promotes.

  • Extend the single annual session to a full day so that staff cover more material in one sitting and the learning is therefore retained for the rest of the year

    Why it is wrong: A longer single session looks like more learning, but cramming more content into one event worsens fatigue and does not stop the rapid decay that already follows the session.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.