CRISC - Information Technology and Security - Section 4.7

Deliver information security awareness training that changes risk-relevant behaviour.

Design and deliver information security awareness training that achieves measurable behaviour change rather than mere compliance tick-box completion. Use techniques such as phishing simulation to test and reinforce awareness, and track improvements in risk-relevant behaviour over time.

Security awarenessTrainingPhishing simulationBehaviour change

Practice question for this objective

Free sampleInformation Technology and Securityeasy

A risk practitioner is asked to show whether the annual security awareness programme is actually reducing risk-relevant behaviour. Leadership currently sees only the percentage of staff who finished the online course. Which measure would best demonstrate that the training is changing behaviour rather than merely being completed or remembered?

  • AThe proportion of staff who opened and read the full course content within the completion deadline that the learning management system enforces each year
  • BThe average score employees achieve on the end-of-module knowledge quiz that the awareness platform delivers immediately after each annual course
  • CThe total count of awareness sessions delivered and the number of staff registered for them across every business unit during the reporting period
  • DThe change over time in the rate at which staff click simulated phishing links and the rate at which they report those suspicious messages to security Correct
Recognise that observed behaviour metrics, not completion, reading or quiz scores, show whether awareness training changes risk-relevant behaviour. Completion, reading logs and quiz scores measure exposure and short-term recall, whereas simulated phishing click and report trends observe real choices under realistic conditions, so a movement in those rates is the evidence the programme is changing behaviour rather than merely being consumed.

Why A is wrong: Reading logs feel deeper than a pass mark, so they tempt as proof of engagement, but they still record consumption of content rather than any change in how staff behave once back at work.

Why B is wrong: Quiz scores look like a solid outcome and are easy to collect, yet they capture recall at the moment of testing, not whether staff apply that knowledge when a real suspicious message arrives.

Why C is wrong: Counting sessions delivered and staff registered is plausible activity reporting, but these are input and reach figures that say nothing about whether risk-relevant behaviour actually changed.

Why D is correct: Click and report rates from phishing simulations observe what staff actually do when tested, so a falling click rate alongside a rising report rate is direct evidence that behaviour has shifted.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Information Technology and Security objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.