CISSP - Security and Risk Management (16% of the exam) - Section 1.12

Establish and maintain a security awareness, education, and training program including periodic reviews and effectiveness evaluation.

Design a security awareness and training programme that addresses social engineering threats, incorporates phishing simulations, and provides role-appropriate education at regular intervals. Evaluate programme effectiveness using measurable metrics so that content and delivery methods can be improved over time.

security awarenessphishing simulationsocial engineeringprogram effectiveness

Practice question for this objective

Free sampleSecurity and Risk Managementeasy

A health technology firm has run the same security awareness e-learning module for three consecutive years. Phishing simulation click rates have plateaued and the latest staff survey shows that most respondents find the content stale. The security manager is preparing a recommendation to the executive sponsor. What should the security manager recommend FIRST?

  • AShorten the existing module to fifteen minutes so that staff are more likely to engage with it next cycle.
  • BIncrease the frequency of phishing simulations from quarterly to monthly to push the click rate down further.
  • CRefresh the awareness programme content and delivery channels based on a review of current threats, audience feedback, and metrics. Correct
  • DOutsource delivery of the awareness module to an external training provider to bring in fresh material.
Use periodic review of the awareness programme, grounded in current threats and metrics, to drive content and channel refresh. The CISSP objective explicitly calls for periodic reviews and effectiveness evaluation of the awareness programme. Plateaued behavioural metrics and audience fatigue are exactly the signals such a review is designed to surface and act on. A structured refresh based on current threats, staff feedback, and observed metrics restores relevance and effectiveness, while tactical moves like shorter modules, more simulations, or outsourcing are downstream decisions that should follow the review rather than precede it.

Why A is wrong: A shorter module may lift completion comfort and looks like a quick win, but trimming stale content does not address the underlying problem that the material no longer reflects current threats or audience needs. It rearranges symptoms rather than treating the cause.

Why B is wrong: More frequent simulations can sharpen vigilance and feel like decisive action, but without refreshed underlying content they tend to produce fatigue and diminishing returns. Simulation cadence is a tactical lever, not a substitute for programme review.

Why C is correct: A periodic review that drives content and channel refresh is the explicit CISSP expectation for sustaining an awareness programme. Anchoring the refresh in current threats, feedback, and metrics ties the change to evidence rather than fashion and addresses the stalled behavioural results.

Why D is wrong: An external provider can be part of the refresh and feels like a clean way to inject new content, but choosing a delivery model before the review is complete skips the diagnostic step. The provider decision is downstream of the periodic review.

See more CISSP practice questions, answers explained.

Exam traps in Security and Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Track the completion rate of the annual module and report the percentage to the audit committee each quarter.

    Why it is wrong: Completion rate is easy to gather and is commonly reported, which makes it tempting, but it only proves attendance, not whether staff behave more securely. CISSP guidance treats attendance metrics as a hygiene minimum, not an effectiveness measure.

  • Agree to the request because consistent disciplinary action is the strongest signal that the organisation takes phishing seriously.

    Why it is wrong: Strict consequences feel like accountability and may appear to drive behaviour, but punishing simulation failures destroys the trust that makes phishing reports possible and trains staff to hide mistakes. CISSP treats simulations as learning tools, not HR triggers.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.