secplus

Dashboard / 5.0 Security Program Management and Oversight

5.6 Given a scenario, implement security awareness practices

Official exam objective outline (6 topics)
  • Phishing
    • Campaigns
    • Recognizing a phishing attempt
    • Responding to reported suspicious messages
  • Anomalous behavior recognition
    • Risky
    • Unexpected
    • Unintentional
  • User guidance and training
    • Policy/handbooks
    • Situational awareness
    • Insider threat
    • Password management
    • Removable media and cables
    • Social engineering
    • Operational security
    • Hybrid/remote work environments
  • Reporting and monitoring
    • Initial
    • Recurring
  • Development
  • Execution

Breakdown 1 — Phishing program

From class — Module C: develop a culture of security awareness; defending against social engineering → train employees.

ElementWhat to do
CampaignsSend simulated phishing regularly; measure click rate and report rate; escalate difficulty over time; never shame — retrain
Recognizing a phishing attemptUrgency/threats, mismatched sender vs. display name, hover the link (look-alike/typosquat domains), unexpected attachments (double extensions), requests for credentials or payment changes, generic greetings
Responding to reported suspicious messagesOne-click "Report phish" button → SOC triages → if malicious: block sender/URL, purge from mailboxes, warn users, thank the reporter

Breakdown 2 — Anomalous behavior recognition

BehaviorExampleResponse
RiskyDisabling AV, using unauthorized cloud storage, plugging in found USBsCoaching, policy reminder, technical block
UnexpectedLogging in at 3 a.m., accessing data outside their role, mass downloadsInvestigate (could be compromise or insider)
UnintentionalEmailing a spreadsheet to the wrong person, misconfiguring a shareFix, train, add guard rails (DLP prompts)

Breakdown 3 — User guidance and training topics

TopicKey message
Policy / handbooksWhere the rules live; sign the AUP
Situational awarenessNotice tailgaters, shoulder surfers, odd emails
Insider threatReport concerning behavior; least privilege applies to everyone
Password managementLong passphrases, no reuse, use the password manager, MFA
Removable media and cablesDon't plug in unknown USB drives or cables; use sheep-dip station
Social engineeringAuthority, urgency, scarcity, familiarity, consensus, intimidation, trust — verify out of band
Operational security (OPSEC)Don't post org charts/badges/travel on social media; clean desk
Hybrid/remote workSecure home Wi-Fi (WPA3), VPN, lock screens, no family on work devices, beware public Wi-Fi/evil twins

Breakdown 4 — Program lifecycle

  • Reporting and monitoring — initial (baseline metrics: phish click rate, quiz scores) and recurring (track improvement; feed results to management).
  • Development — build content for roles (developers → secure coding; finance → BEC; execs → whaling).
  • Execution — onboarding training, annual refreshers, just-in-time micro-training after a simulated-phish click, posters/newsletters.

Exam tip: "Employee reports a suspicious email — what next?" → analyze it, don't click it; contain if malicious. "Reduce phishing success org-wide" → campaigns + training (technical controls help, but the objective is awareness). "User keeps disabling the screen saver" → risky behavior → coaching + technical enforcement. "Measure whether training works" → recurring reporting/metrics.

Quick self-check

  • Three signs of a phishing email?
  • Risky vs. unexpected vs. unintentional behavior?
  • What's OPSEC in a home-office context?

Sources: 20260917_173252.jpg, 20260917_173259.jpg, 20260917_173312.jpg