An organization performed a risk assessment and discovered that less than 50% of its employees have been completing security awareness training. Which of the following should the Chief Information Security Officer highlight as an area of Increased vulnerability in a report to the management team?
The Chief Information Security Officer (CISO) should highlight social engineering as an area of increased vulnerability due to the lack of completion of security awareness training by employees. Social engineering attacks exploit human behavior, and employees who are not adequately trained are more likely to fall victim to phishing, pretexting, and other types of social engineering tactics. Increasing awareness and training helps employees recognize and respond appropriately to these threats.
CompTIA CASP+ CAS-004 Exam Objectives: Section 4.3: Understand how to conduct risk management activities.
CompTIA CASP+ Study Guide, Chapter 9: Risk Management and Incident Response.
Chauncey
10 months agoAnglea
10 months agoTracey
10 months agoIra
10 months agoLeslie
10 months agoLenna
9 months agoVon
9 months agoGail
10 months agoIlene
10 months agoZachary
10 months agoLaura
9 months agoPatrick
9 months agoVerona
10 months agoDaron
10 months agoIsadora
10 months ago