How should Learning Objectives be created with respect to an organization’s managed risks?
Learning objectives should be defined separately for each managed risk so that the required learner knowledge or behavior directly supports treatment of that specific risk. Department-wide, company-wide, and threat-agent-based documents do not maintain that direct risk-to-objective traceability.
Community Discussion