An organization performed a risk assessment and discovered that less than 50% of its employees have been completing security awareness training. Which of the following should the Chief Information Security Officer highlight as an area of Increased vulnerability in a report to the management team?
The Chief Information Security Officer (CISO) should highlight social engineering as an area of increased vulnerability due to the lack of completion of security awareness training by employees. Social engineering attacks exploit human behavior, and employees who are not adequately trained are more likely to fall victim to phishing, pretexting, and other types of social engineering tactics. Increasing awareness and training helps employees recognize and respond appropriately to these threats.
CompTIA CASP+ CAS-004 Exam Objectives: Section 4.3: Understand how to conduct risk management activities.
CompTIA CASP+ Study Guide, Chapter 9: Risk Management and Incident Response.
Chauncey
2 months agoAnglea
2 months agoTracey
3 months agoIra
3 months agoLeslie
3 months agoLenna
2 months agoVon
2 months agoGail
2 months agoIlene
3 months agoZachary
3 months agoLaura
2 months agoPatrick
2 months agoVerona
2 months agoDaron
2 months agoIsadora
3 months ago