QuestionQ726

Governance

Which of the following is the MOST important subject to include in a risk-awareness training program for all staff?

  • A The risk department's roles and responsibilities.
  • B Policy compliance requirements and exceptions process.
  • C The organization's information security risk profile.
  • D Internal and external information security incidents.
Explanation

All personnel need to understand and follow the organization’s information-security policies and the authorized process for exceptions, because exceptions that bypass approval can create unmanaged risk. Security awareness is foundational training for all personnel and is intended to communicate their role in protecting assets, including acceptable uses and risks to organizational systems. NIST awareness-training glossary

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!