Question: I need help with this question for my risk management class. Your organization has the following statements regarding phishing/social engineering in the employee manual: All

I need help with this question for my risk management class.

Your organization has the following statements regarding phishing/social engineering in the employee manual:

  • All employees are required to complete annual security awareness training as provided by the Information Security team. Employees must successfully complete the training and achieve an established minimum score on any quizzes associated with the training.
  • The organization will conduct routine evaluations of the effectiveness security awareness training through simulated phishing tests. Employees that incorrectly identify simulated phishing emails must complete additional security awareness training and their manager will be notified. If an employee incorrectly identifies 3 or more simulated phishing emails, additional action may be taken by the employees manager, up to and including termination.
  • Employees are required to report any suspicious emails to the organizations Information Security team using the Suspicious Mail button located in the organizations email program. Employees clicking on malicious links will be required to complete additional security awareness training. Repeated occurrences will be subject to additional personnel action as determined by the employees manager and HR.

The top salesperson in the organization (who brings in 22% of the companys net sales) has completed the security awareness training but has failed 4 of the last 5 phishing tests and clicked on 3 bad links in the past 6 months. If you were the CIO, how would you address the situation?

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related General Management Questions!