QuestionQ104

Incident and Risk Management

A global financial institution recently updated its Information Security Governance and Compliance Program in response to evolving cyber threats and regulatory changes. The revised program includes enhanced policies, updated employee training modules, a restructured cybersecurity team, and increased budget allocation for security tools.

Six months after implementation, a routine audit identified compliance gaps with the new policies, particularly in overseas branches. The institution must now determine the most effective administrative control to achieve stronger adherence to its updated security governance and compliance standards. What should be its primary focus?

  • A Conducting regular, comprehensive audits of all branches.
  • B Enhancing employee training and awareness programs globally.
  • C Restructuring the cybersecurity team to focus on international compliance.
  • D Implementing advanced cybersecurity technologies across all branches.
Explanation

Security awareness and training are administrative controls that help employees understand policy requirements and apply them consistently in their work. A globally reinforced training and awareness program directly addresses the observed policy-compliance gaps across overseas branches; audits primarily detect deficiencies, while organizational restructuring and technical tools do not by themselves establish employee adherence. NIST guidance identifies security awareness, behavior change, and role-based learning as core elements of an organizational cybersecurity learning program.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!