A simulated phishing message is sent to every member of staff, including those with no IT responsibilities, and the click rate is measured. This programme is best classified as:
A simulated phishing message is sent to every member of staff, including those with no IT responsibilities, and the click rate is measured. This programme is best classified as:
Answer
security awareness
Options - A. security awareness - B. role-based training - C. security education - D. a penetration test of the mail gateway Why - A. Correct — it focuses attention on an issue, reaches every employee, is short and repeated, and is assessed by recognition rather than by skill. - B. Training builds a skill for a role and is assessed by whether the learner can apply it. Everyone receiving it is the tell that this is not role-based. - C. Education builds understanding and insight over a career and is assessed by interpretation. - D. A penetration test attacks the technical controls; this exercise measures human behaviour and does not attempt to defeat the gateway. Awareness focuses attention; training builds a skill; education builds understanding. Audience breadth and assessment method are the two fastest discriminators.
Stallings & Brown 5e ch17 §17.1–17.4; NIST SP 800-50; NIST SP 800-61; ISO/IEC 27002