An organization performed a risk assessment and discovered that less than 50% of its employees have been completing security awareness training. Which of the following should the Chief Information Security Officer highlight as an area of Increased vulnerability in a report to the management team?
The Chief Information Security Officer (CISO) should highlight social engineering as an area of increased vulnerability due to the lack of completion of security awareness training by employees. Social engineering attacks exploit human behavior, and employees who are not adequately trained are more likely to fall victim to phishing, pretexting, and other types of social engineering tactics. Increasing awareness and training helps employees recognize and respond appropriately to these threats.
CompTIA CASP+ CAS-004 Exam Objectives: Section 4.3: Understand how to conduct risk management activities.
CompTIA CASP+ Study Guide, Chapter 9: Risk Management and Incident Response.
Chauncey
1 months agoAnglea
1 months agoTracey
1 months agoIra
1 months agoLeslie
1 months agoLenna
12 days agoVon
19 days agoGail
26 days agoIlene
1 months agoZachary
1 months agoLaura
23 days agoPatrick
24 days agoVerona
27 days agoDaron
1 months agoIsadora
2 months ago