CISSP - Security and Risk Management - Section 1.12

Establish and maintain a security awareness, education, and training program including periodic reviews and effectiveness evaluation.

Design a security awareness and training programme that addresses social engineering threats, incorporates phishing simulations, and provides role-appropriate education at regular intervals. Evaluate programme effectiveness using measurable metrics so that content and delivery methods can be improved over time.

security awarenessphishing simulationsocial engineeringprogram effectiveness

Practice question for this objective

Free sampleSecurity and Risk Managementeasy

A health technology firm has run the same security awareness e-learning module for three consecutive years. Phishing simulation click rates have plateaued and the latest staff survey shows that most respondents find the content stale. The security manager is preparing a recommendation to the executive sponsor. What should the security manager recommend FIRST?

  • AShorten the existing module to fifteen minutes so that staff are more likely to engage with it next cycle.
  • BIncrease the frequency of phishing simulations from quarterly to monthly to push the click rate down further.
  • CRefresh the awareness programme content and delivery channels based on a review of current threats, audience feedback, and metrics. Correct
  • DOutsource delivery of the awareness module to an external training provider to bring in fresh material.
Use periodic review of the awareness programme, grounded in current threats and metrics, to drive content and channel refresh. The CISSP objective explicitly calls for periodic reviews and effectiveness evaluation of the awareness programme. Plateaued behavioural metrics and audience fatigue are exactly the signals such a review is designed to surface and act on. A structured refresh based on current threats, staff feedback, and observed metrics restores relevance and effectiveness, while tactical moves like shorter modules, more simulations, or outsourcing are downstream decisions that should follow the review rather than precede it.

Why A is wrong: A shorter module may lift completion comfort and looks like a quick win, but trimming stale content does not address the underlying problem that the material no longer reflects current threats or audience needs. It rearranges symptoms rather than treating the cause.

Why B is wrong: More frequent simulations can sharpen vigilance and feel like decisive action, but without refreshed underlying content they tend to produce fatigue and diminishing returns. Simulation cadence is a tactical lever, not a substitute for programme review.

Why C is correct: A periodic review that drives content and channel refresh is the explicit CISSP expectation for sustaining an awareness programme. Anchoring the refresh in current threats, feedback, and metrics ties the change to evidence rather than fashion and addresses the stalled behavioural results.

Why D is wrong: An external provider can be part of the refresh and feels like a clean way to inject new content, but choosing a delivery model before the review is complete skips the diagnostic step. The provider decision is downstream of the periodic review.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security and Risk Management objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.