Security Awareness Ecosystem, and Culture Flashcards
1
Q
What is cybersecurity awareness all about?
A
- Recognising IT security concerns
- Change user behaviour
- User as first line of defense
- Applicable to all users in the organisation
2
Q
What are the three critical elements to ensure sustained executive support for security awareness?
A
- Vision
- Metrics
- Communicating business value
3
Q
What are the objectives for a security awareness program?
A
- Educate
- Change
- Organisational learning
4
Q
What are the characteristics of a learning continuum layer?
A
- Awareness
- Training
- Education
5
Q
What are the characteristics of understanding your environment in security awareness training?
A
- Roles and responsibilities
- Budget
- Stakeholders
- Culture
- Policies
- Business
6
Q
How to design a cyber security awareness program?
A
- Identify Awareness Program
- Conduct a Needs Assessment to determine the baseline
- Determine sources and methods of a needs assessment
- Develop awareness program materials
- Identify best delivery method
- Communicate
- Metrics and monitoring
- Regular audit
7
Q
How to implement a cybersecurity-first culture?
A
- Implement security awareness training
- Establish accountability
- Embed it into the organisation’s core values
8
Q
What is a cyber ecosystem?
A
A variety of participants that interact with multiple purposes to help each other!
9
Q
What kind of Awareness Program Model exist?
A
- Centralised Program Management Model
- Partially Decentralized Program Management Model
- Fully Decentralized Program Management Model