CISSP Certification Guide / Chapter 6
Security Policies, Training, and Awareness
The document stack that turns management intent into mandatory behavior, the personnel controls that run from screening to termination, and the awareness, training, and education program that keeps the human layer of the program honest.
The control that is written before it is installed
Consider what the security program actually consists of at the end of the day. Firewalls, directories, encryption, monitoring, patching: each of those is a technical control with an owner, a maintenance cycle, and a failure mode. But every one of them was preceded by a document and a decision. Someone decided that a firewall belonged at the perimeter, someone wrote down which traffic is allowed and who may approve an exception, someone decided which systems are subject to the rule, and someone decided what happens to an employee who routes sensitive data around the control. That layer, the layer of written direction and human conduct, is not the paperwork that surrounds the real security. It is where security either becomes enforceable or never existed at all.
This chapter is about that layer. It treats three loops that the CISSP exam keeps circling, because they are the three places where the manager view and the technician view diverge most sharply. The first loop is the document loop: the hierarchy of policy, standard, baseline, guideline, and procedure, and the difference between direction that binds and direction that advises. The second loop is the employment loop: the personnel controls that attach to a person from the moment a position is designed until long after they have left, including screening, agreements, separation of duties, job rotation, and termination. The third loop is the attention loop: the security awareness, training, and education program that keeps the first two loops from decaying, because documents age and people forget.
The exam treats all three as administrative controls, and that label is the key to how questions about them are written. An administrative control does not stop an attacker at a network boundary. It shapes how an organization decides, who is allowed to do what, and what people actually do under pressure. That makes administrative controls cheap to draft and expensive to make real, which is why so many exam scenarios turn on a tiny distinction: mandatory versus recommended, before hire versus after hire, awareness versus training. Learn to place the fact in the right loop and the rest of the question usually answers itself.
The document stack: policy, standard, baseline, guideline, procedure
Organizations govern behavior with a stack of documents, and the first skill the exam tests in this area is telling the layers apart. NIST Special Publication 800-12 Revision 1, “An Introduction to Information Security,” defines the stack cleanly, and it is the reference worth holding. In that model, the information security policy is the aggregate of directives that set the organization’s security direction: what it protects, why it protects it, who is responsible, and how compliance is measured. Policy is written at a high level on purpose. It says what must happen, not how to do it, because the “how” changes constantly while the “what” should survive a technology refresh.
Below the policy sit standards. In the language of SP 800-12 Rev 1, organizational standards specify uniform use of specific technologies, parameters, or procedures where uniformity benefits the organization, and they are normally compulsory. A standard is the place where an abstract commitment in the policy, such as “sensitive data must be protected at rest,” becomes a concrete mandate: “all laptops that leave the building must use full-disk encryption with the approved product, and recovery keys must be escrowed in the key management system.” Employees do not choose to follow a standard; they follow it, or they are out of policy. That compulsory character is the discriminator the exam uses: a standard binds, a guideline suggests.
Guidelines are the discretionary layer. SP 800-12 Rev 1 describes them as assisting users and system personnel in securing their systems while recognizing that systems vary and that imposing a uniform standard is not always achievable, appropriate, or cost-effective. A guideline might recommend a particular secure configuration for a common server type, with the understanding that a team may deviate where the environment demands it. The word that matters is “recommend”: a guideline is advice with reasons, and an organization that treats a guideline as an absolute has confused its own stack.
Baselines sit with the standards in the mandatory family, but they mean something narrower. A baseline is the minimum acceptable configuration or control set for a class of systems. The federal world gives the cleanest example: NIST Special Publication 800-53 defines baseline control sets for systems at low, moderate, and high impact, so that an agency starting a security assessment can select the low, moderate, or high baseline and then tailor it to its own risk. The concept transfers to everyday operations: a hardened server image that every new build must match, or a minimum patch level below which a machine is not allowed on the network. A baseline is a floor, not a ceiling. Every system may rise above it; nothing may fall below it.
Procedures are the bottom of the stack and the most specific documents in it. SP 800-12 Rev 1 calls them the detailed steps followed to accomplish a particular task: how to create a user account with the right privileges, how to respond to a firewall alert, how to restore a database. Procedures are where policy becomes executable by a person who has never thought about policy. They are also the layer most likely to be wrong, because they describe reality, and reality changes. When a procedure and a standard disagree, the organization has a maintenance problem, not a mystery.
The ordering rule that organizes the whole stack runs from abstract to concrete and from mandatory to optional: policy and standards and baselines bind, guidelines recommend, and procedures execute. The exam asks which of these is mandatory, which is recommended, and which is the most detailed, and candidates who can answer all three questions without hesitation are rare enough that it is worth making them reflexive.
Two more distinctions matter before the stack is complete. First, policies, standards, and procedures can all be issued at different scopes: organization-wide, department-wide, or system-specific, and the scope should be stated in the document itself so that nobody has to guess. Second, the stack is a hierarchy of authority. When documents conflict, the higher document wins, and deviations from standards or baselines should be explicit exceptions approved at the level the document names, not silent shortcuts. A security program that tolerates quiet deviation has already learned the wrong lesson from its own stack.
Three flavors of policy and the approval ladder
SP 800-12 Rev 1 classifies policy itself into three types, and the classification is worth owning because it reappears in exam scenarios as descriptions of documents. Program policy establishes the information security program itself: its purpose and goals, its scope, the assignment of responsibilities, and the compliance structure, including the authorization to create penalties and disciplinary actions for violations. It is the founding document, the one that says the program exists, what it protects, and who runs it. In the federal model, a management official, typically the senior information security officer, issues program policy.
Issue-specific policy addresses a single topic or area of current relevance to the organization, and it is written to be clear to ordinary users. Remote work rules, acceptable use of email and internet, social media conduct, personal device use, data classification and handling: each of these earns its own issue-specific policy. The distinguishing features are breadth of audience, everyone affected, and frequency of change, because technology and threats move faster than the program-level documents can. SP 800-12 Rev 1 notes that issue-specific policies must be reviewed regularly precisely because the technologies they govern change often. A well-formed issue-specific policy states its purpose, its applicability, the roles and responsibilities it creates, and the consequences of noncompliance.
System-specific policy is the narrowest type. It governs a single system or a small group of related systems and spells out the security objectives for that system, the operational security rules that apply to it, and how the policy will be implemented. Where the program policy says why security exists and the issue-specific policy says what the rules are for a topic, the system-specific policy says what the rules are for this particular machine, this particular application, this particular network segment. It is the point where policy shades into configuration, and it is the document a system owner actually works from.
A second, older way of slicing policies also shows up in the field and on the exam: regulatory, advisory, and informative. Regulatory policies implement obligations that come from outside the organization, from law, regulation, or contract, and compliance is not optional. A data protection policy that exists because the organization processes personal data under the GDPR is regulatory in character. Advisory policies express senior management’s preferred practices, recommended behavior that the organization encourages and may sanction when ignored, but that is not compelled by an external obligation. Informative policies exist to educate: they explain the reasons behind the rules, or they address behavior outside the enforcement boundary, such as how employees should protect their home computers. The exam sometimes asks which type applies to a given rule, and the quick test is to ask where the obligation comes from: outside law, inside management preference, or neither, just enlightenment.
Then there is the approval ladder, and this is where the governance layer from Chapter 3 reaches into the document stack. A policy binds the organization because it carries the authority of the level that issued it. In the corporate model, the top-level policy is approved by senior management, and in many organizations by the board, because it commits the whole organization to a direction and it is the basis for holding any employee accountable. The security team drafts, legal and human resources review, and the accountable management layer approves and owns. Standards and procedures, being more technical, are usually approved at the level of the security executive or the process owner, with the authority the program policy delegated to them. The pattern the exam rewards is simple: authority flows down, so the higher the document sits in the stack, the higher the level that must own it.
Every policy in the stack has a lifecycle. It is identified as needed, drafted, reviewed by the functions that must live with it, approved at the right level, published, communicated to the people it binds, enforced, reviewed on a schedule, and eventually revised or retired. The two cadence facts the exam leans on are that policies should be reviewed at least annually and again after any material change in the business, the threat environment, or the regulations that drive them, and that a policy nobody communicated is a policy nobody follows. Communication is part of the policy’s existence, not an optional sequel, which is why it is published through the awareness program and why employees are typically required to acknowledge the documents that bind them.
Personnel security: the employment lifecycle as a control loop
The document stack says what the rules are. The personnel controls decide who gets to be inside the wall at all, and they run on a different clock: the employment lifecycle. NIST SP 800-53 Revision 5 packages these controls in the Personnel (PS) family, and the ISO family of standards carries a parallel set in the people controls of ISO/IEC 27002:2022. The exam tests the lifecycle phase you are in and what belongs there, so it is worth walking the loop in order.
Before hire, the organization designs the position and the risk that goes with it. PS-2, position risk designation, asks what access and responsibility the role carries and assigns it a risk level, which in turn drives how deep the screening must go. A systems administrator with privileged access to the whole environment screens differently from an intern who never touches production. PS-3, personnel screening, then does the work: verification of identity, employment history, education, references, and criminal and credit checks where law and the role justify them. The proportionality principle from ISO/IEC 27002:2022 control 6.1 says it plainly: background verification checks should be conducted before joining, consistent with applicable law and ethics, and proportional to the business requirements, the class of information the person will access, and the perceived risks. The exam’s favorite wrong answer in this corner is screening everyone at the maximum depth regardless of role, which fails the proportionality test, or doing the check after the person already has access, which fails the sequence.
At hire, the person becomes a member of the workforce and signs the agreements that make the program enforceable. ISO/IEC 27002:2022 control 6.2 requires that terms and conditions of employment state the responsibilities for information security and the consequences of failing to meet them, and control 6.6 addresses confidentiality or non-disclosure agreements, which survive employment and bind the person after they leave. NIST SP 800-53 PS-6, access agreements, collects the same idea: nondisclosure agreements and acceptable use agreements are signed before access is granted. The acceptable use policy is the issue-specific policy most employees know by name, and its signature is not a formality; it is the hook on which every later sanction and every court enforcement hangs. Onboarding also plugs the new employee into the awareness program on day one, which is where the attention loop of this chapter meets the employment loop.
During employment, the controls shift from entry to ongoing conduct. The classic quartet the exam returns to is least privilege, separation of duties, job rotation, and mandatory vacation. Least privilege, which Chapter 19 treats in full with access control, grants each person only the access their current role needs; it is a personnel rule as much as a technical one, because it is the personnel office that reviews whether a person’s entitlements still match the role. Separation of duties splits a sensitive action into steps that no single person may complete alone, so that creating a vendor and approving a payment to that vendor are two people’s jobs, or two different controls’ jobs. Its purpose is to make fraud and error require collusion, and its limit is that collusion exists, which is why it is paired with the next two controls. Job rotation moves people through roles so that no one owns a function long enough to conceal abuse, and mandatory vacation forces the same effect: someone else runs the function while the owner is away, and discrepancies surface. ISO/IEC 27002:2022 control 6.4 covers the backstop, a formal disciplinary process for personnel who violate information security, communicated in advance and applied consistently, and SP 800-53 PS-8, personnel sanctions, plays the same role in the federal model.
The exam likes to test the reasons behind these controls, not just the names. Separation of duties exists because a single person controlling both halves of a transaction can fabricate and approve it; the answer that says it prevents collusion is pointing at its limit, not its purpose. Job rotation and mandatory vacation work by making concealment hard, which is why an auditor recommends them in an environment where one employee has run a financial process alone for years. Least privilege and separation of duties are related but not the same: least privilege limits the damage one compromised account can do, separation of duties prevents one person from completing a whole high-risk process. When a scenario describes two people required for one action, the control is separation of duties or dual control, and when it describes trimming an account’s rights, the control is least privilege.
Transfers are the phase most organizations mishandle, because nobody thinks of a move as a security event. NIST SP 800-53 PS-5, personnel transfer, and ISO/IEC 27002:2022 control 6.5 both insist that a change of employment means a review of access rights: the person’s new role is analyzed, the access the old role required is removed or adjusted, and the access the new role requires is granted on a need-to-know basis. The exam scenario to watch for is the employee who moved departments six months ago and still holds administrator rights from the old job. The correct response is to re-review and re-scope entitlements at the transfer, not to wait for an annual audit to find the ghost access.
Termination closes the loop, and the discipline here is sharp. At termination, and the exam will test “when,” the organization revokes logical and physical access at the point of departure, disables accounts, collects badges, keys, tokens, and equipment, conducts an exit interview, reminds the departing person of obligations that survive, such as the nondisclosure agreement, and completes a handover of duties and knowledge. SP 800-53 PS-4, personnel termination, carries the federal version, and ISO/IEC 27002:2022 control 6.5 covers the continuing responsibilities after termination or change. For an involuntary termination, the revocation typically happens at or before the moment the person is told, because a terminated employee with working credentials is a sabotage waiting for a schedule. The exam’s discriminating detail is usually temporal: access is revoked at termination, not at the end of the week, not after the knowledge transfer, not on the last payroll run.
Three supporting facts complete the personnel picture. Contractor and third-party personnel are subject to the same discipline, handled through the contract, which is the point of SP 800-53 PS-7, external personnel security: the organization cannot fire a vendor’s employee, so it contracts for screening and termination duties instead. Noncompliance is treated as a process with a range of outcomes, from retraining to sanction, and SP 800-12 Rev 1 makes a humane point worth remembering: violations are often unintentional and the result of missing knowledge or training, so the response ladder should include education before punishment. And every phase produces records, because a control that cannot prove it happened did not happen, which is why screening records, signed agreements, and training records are kept and audited.
Awareness, training, and education: the attention loop
The third loop is the one that keeps the first two alive. Documents decay on the shelf, and people forget what they signed, so every mature security program runs a deliberate program of security awareness, training, and education, a bundle often called SETA. The definitions that anchor the exam come from NIST Special Publication 800-50, “Building an Information Technology Security Awareness and Training Program,” which in turn draws on SP 800-16. They form a learning continuum, and the exam loves to ask which rung a described activity occupies.
Awareness is the broadest and thinnest rung. SP 800-50 is explicit that awareness is not training: the purpose of awareness presentations is simply to focus attention on security, to allow individuals to recognize security concerns and respond accordingly, and to change behavior or reinforce good practice. In awareness activities the learner is a recipient of information, and the medium is packaging: posters, newsletters, security moments in team meetings, brief phishing awareness messages, short quizzes. The goal is not skill, it is attention and attitude. An employee who knows to report a suspicious email because a campaign reminded them is the product of awareness.
Training is the next rung, and it produces skill. SP 800-50 defines training as the level of the continuum that strives to produce relevant and needed security skills and competencies in practitioners of functional specialties other than information security: managers, developers, auditors, system administrators. Where awareness says “this is a phishing email,” training says “here is how you analyze a suspicious message, and here is how you test your application for injection flaws.” Training is role-based, it has measurable objectives, and it is what ISO/IEC 27001:2022 means in clause 7.2 when it requires the organization to determine the competence needed by people whose work affects information security and to ensure they are competent through education, training, or experience. Training is where a generic security awareness session stops being enough, which is why privileged users, developers, and incident responders each need their own curricula.
Education is the deepest rung. SP 800-50 describes it as integrating the skills and competencies of the various specialties into a common body of knowledge, adding a multidisciplinary study of concepts, issues, and principles, and producing information security specialists capable of vision and proactive response. A degree program, a deep professional curriculum, the kind of study that builds the specialist, is education. The exam distinguishes the rungs by outcome: awareness changes attention and behavior, training changes capability on the job, education changes the person’s depth of understanding. The mnemonic that survives the exam room is what, how, why: awareness is what to watch for, training is how to do the job, education is why the discipline works, which is the foundation for adapting when the world changes.
The obligations around this program are concrete in the standards. ISO/IEC 27001:2022 clause 7.3 requires the organization to ensure that persons doing work under its control are aware of the information security policy, of their contribution to the effectiveness of the information security management system, including the benefits of improved performance, and of the implications of not conforming with its requirements. ISO/IEC 27002:2022 control 6.3 spells out the operational control: personnel receive appropriate awareness education and training, and updates on a regular basis. NIST SP 800-53 Rev 5 distributes the same duties across the awareness and training (AT) family: AT-2 for literacy training and awareness, AT-3 for role-based training, and AT-4 for training records that document and monitor individual training activities. In the payment card world, PCI DSS v4.0 Requirement 12.6 requires a security awareness program with training performed upon hire and at least annually (12.6.1) and role-specific training for personnel with cardholder data responsibilities (12.6.2). And in the privacy world, the GDPR gives the data protection officer an explicit duty under Article 39(1)(a) to inform and advise the controller and employees who carry out processing, which makes privacy awareness a named legal role, not a volunteer effort.
Program design follows the same shape in every framework. Start at onboarding, because the first week is when expectations are set. Run a baseline awareness program for everyone, refreshed at least annually, because the threat landscape and the rules both move. Layer role-based training on top for the roles that hold more risk, using the job’s actual tasks, and here the NICE Framework, NIST SP 800-181 Rev 1, offers a public vocabulary of work roles, tasks, and competencies that a program can map its curricula against. Reinforce between formal sessions with campaigns and simulations, because retention decays on a curve. And design for adults: the content has to be relevant to the learner’s actual work, practical rather than abstract, spaced rather than crammed, and interactive enough that the learner does something, not just reads something. A program that treats awareness as a thirty-minute annual video has checked a box; a program that treats it as a behavior-change effort has a chance of working.
Measuring the human control
Administrative controls are controls, and controls are measured. The exam’s manager-perspective questions in this area are almost always about what constitutes evidence that the program works, and the wrong answers are the ones that mistake activity for outcome. Completion rates are activity: they prove that people sat through the material, which is necessary and nowhere near sufficient. Satisfaction surveys prove that people enjoyed it, which correlates with nothing in particular. The evidence that matters is behavioral, and it accumulates over time.
The classic behavioral measures are the phishing simulation click rate, the report rate for suspicious messages, assessment scores before and after training, the rate of security incidents attributed to human error, and the time between a suspicious event and a report. A program that works shows a click rate that falls across successive simulations, a report rate that rises, and an incident count driven by human error that trends down while the population and the threat level stay comparable. SP 800-50 was written for exactly this discipline: it calls for a needs assessment to design the program, and for evaluation to confirm that the program achieves its goals, because an unmeasured awareness program is a hope with a budget.
The exam twists on this topic take two forms. One is the single-snapshot trap: a manager sees one month of high click rates and declares the program a failure, when the correct analysis is the trend across campaigns and the comparison against a baseline. The other is the attribution trap: a program cannot be judged by raw incident totals, because total incidents rise when reporting improves, and the program’s own effect is to surface more of what used to stay hidden. The sophisticated answer separates reporting quality from underlying behavior, which is why mature programs track both the click rate and the report rate, and why the discussion of a “good” phishing rate always has a baseline in it.
The manager-perspective pattern
Every question this chapter feeds has a governance skeleton, and the skeleton has five joints. Who drafts: the security team, with legal and human resources consulted where the document touches law, employment, or discipline. Who approves: the accountable management layer, higher for higher documents, board or senior executives for the top-level policy. Who enforces: management throughout the organization, with the security team monitoring and advising and internal audit providing independent assurance, the three-lines pattern from Chapter 3. Who complies: everyone, because a policy that exempts a department is a policy with a hole. And who measures: the program owner, with metrics reported upward so the board can see whether the human layer is actually changing.
When a scenario asks for the best response to a policy gap, a training lapse, or a personnel action, place the fact in its loop first. A missing standard for laptop encryption is a document-stack problem: write the standard, set the baseline, publish it. An employee who still has old-department access is an employment-loop problem: re-scope entitlements at the transfer. A workforce that keeps falling for phishing is an attention-loop problem: measure the click trend, refresh the awareness campaign, and retrain the repeat offenders, with discipline reserved for the pattern that survives education. The wrong answers in this area are usually the ones that jump a loop: punishing an employee for a knowledge gap that training should close, or writing a procedure where only a standard will bind.
Practice questions
-
An organization’s security team drafts a document that mandates a specific encryption algorithm, minimum key length, and escrow arrangement for all laptop storage, and states that compliance is required. What is this document?
A. A guideline. B. A standard. C. A policy. D. A procedure.
-
Which element of the documentation stack is best described as recommended rather than mandatory, with latitude to deviate where the environment justifies it?
A. A baseline. B. A standard. C. A guideline. D. A program policy.
-
A company issues a document addressed to all employees stating that remote work requires the corporate VPN and multi-factor authentication, defining who it applies to, the responsibilities it creates, and the consequences of noncompliance. How would NIST SP 800-12 Rev 1 classify this document?
A. Program policy. B. Issue-specific policy. C. System-specific policy. D. A security baseline.
-
The CISO has drafted a revised top-level information security policy and wants it to bind the entire organization. Who must approve it for that to happen?
A. The CISO alone, as the author and program owner. B. The incident response team, as the users of the policy. C. Senior management, and in many organizations the board. D. The internal audit function, to preserve independence.
-
Before granting a candidate access to a privileged financial system, the organization assigns the position a risk level and conducts a background investigation proportional to that risk. Which NIST SP 800-53 control family are these actions drawn from?
A. The Awareness and Training (AT) family. B. The Personnel (PS) family. C. The Contingency Planning (CP) family. D. The Access Control (AC) family.
-
A finance process requires two different employees to complete a payment transaction, no single employee may both create and approve a vendor, and staff rotate through the process annually with mandatory two-week vacations. What is the primary purpose of this combination?
A. To reduce password fatigue among finance staff. B. To make fraud and error require collusion or exposure. C. To ensure at least two employees can operate any system. D. To reduce the attack surface available to malware.
-
An employee is terminated effective immediately on a Friday morning. Which access-related response is correct?
A. Disable the accounts and revoke the badge at the moment of termination, collect equipment, and conduct an exit interview. B. Leave accounts active until Monday so the employee can complete the knowledge transfer. C. Disable network access but allow email access until the end of the pay period. D. Revoke access after the employee returns the laptop, to avoid damaging the handover.
-
A quarterly email campaign teaches employees how to recognize phishing messages, reinforces the reporting channel, and ends with a short quiz. Which rung of the learning continuum is this?
A. Education. B. Training. C. Awareness. D. Certification.
-
A security team designs a hands-on course for system administrators that teaches them to configure firewalls, harden servers, and respond to alerts, with a pass/fail assessment at the end. Which rung of the learning continuum is this?
A. Awareness. B. Training. C. Education. D. Socialization.
-
Under ISO/IEC 27001:2022, which three items must persons doing work under the organization’s control be aware of?
A. The risk register, the incident response plan, and the asset inventory. B. The information security policy, their contribution to the effectiveness of the information security management system, and the implications of not conforming with its requirements. C. The audit schedule, the disaster recovery plan, and the vendor contracts. D. The firewall rules, the backup schedule, and the encryption keys.
-
A company’s phishing simulation program shows a click rate that fell from 14 percent in the first campaign to 6 percent in the third, while the rate of reported suspicious messages rose over the same period. What is the soundest interpretation?
A. The program is working: behavior changed in the intended direction across campaigns. B. The program failed, because any click rate above zero is unacceptable. C. The result is meaningless, because simulations cannot measure behavior. D. The program should be cancelled, because reporting increased total incident counts.
-
An internal audit finds that an employee who transferred departments eight months ago still holds administrator rights to the old department’s systems, and that several contractors retain access from terminated projects. What is the correct corrective action?
A. Wait for the next annual review, when all access is recertified. B. Re-review and re-scope entitlements at transfer and project end, removing access no longer required by the current role. C. Grant the employees more access so the old privileges are justified. D. Deactivate the old systems instead of changing the access.
Answers and rationales
-
B. A standard specifies uniform use of specific technologies, parameters, or procedures and is normally compulsory, which is exactly what a mandate for a specific algorithm, key length, and escrow arrangement is. A policy states direction at a high level without choosing the technology (option C), a guideline is recommended rather than mandatory (option A), and a procedure is a set of detailed steps for a task (option D).
-
C. Guidelines assist users in securing systems while recognizing that environments vary and that uniform standards are not always achievable, appropriate, or cost-effective; they are the recommended layer. Baselines are mandatory minimums (option A), standards are compulsory (option B), and program policy binds the whole program (option D).
-
B. An issue-specific policy addresses a single topic of current relevance, is written to be clear to all affected users, and states purpose, applicability, responsibilities, and consequences, which matches a remote work policy. Program policy establishes the program itself (option A), system-specific policy governs one system or small group (option C), and a baseline is a minimum configuration, not a people-facing rule (option D). SP 800-12 Rev 1 also notes that issue-specific policies must be reviewed regularly because the technologies they govern change frequently.
-
C. A policy binds the organization because it carries the authority of the level that issued it, so the top-level policy is approved by senior management, and in many organizations by the board. The author and program owner (option A) cannot grant the document the whole organization’s authority by themselves. The incident response team is a consumer of the policy, not its approver (option B), and internal audit’s independence is compromised if it approves what it later audits (option D).
-
B. Position risk designation and personnel screening are the PS-2 and PS-3 controls in the Personnel (PS) family of NIST SP 800-53. The AT family governs awareness and training (option A), CP governs contingency planning (option C), and AC governs access enforcement (option D).
-
B. Separation of duties makes a single person unable to complete a high-risk process, and job rotation with mandatory vacation makes concealment hard by putting other people in the workflow. The combination exists to force fraud and error to require collusion or exposure. Password fatigue (option A), operational redundancy (option C), and malware defense (option D) are different objectives served by different controls.
-
A. Access is revoked at termination: accounts disabled and the badge revoked at the moment of departure, equipment collected, and an exit interview held, with obligations like the nondisclosure agreement reaffirmed. For an involuntary termination, revocation happens at or before the person is told, which rules out options B, C, and D, all of which leave working credentials in the hands of a departing employee.
-
C. Awareness focuses attention on security, aims to change behavior or reinforce good practice, and treats the learner as a recipient of information, which is what a campaign with reinforcement messages and a short quiz does. Training builds job skills with measurable objectives (option B), education produces security specialists through deep study (option A), and certification is a credential, not a rung of the learning continuum (option D). NIST SP 800-50 is explicit that awareness is not training.
-
B. Training strives to produce relevant and needed security skills and competencies for practitioners, with a measurable outcome, which is exactly a hands-on firewall and hardening course with an assessment. Awareness only focuses attention (option A), and education integrates a multidisciplinary body of knowledge to produce specialists capable of vision and proactive response (option C).
-
B. Clause 7.3 of ISO/IEC 27001:2022 requires awareness of the information security policy, of the person’s contribution to the effectiveness of the information security management system, including the benefits of improved information security performance, and of the implications of not conforming with the system’s requirements. The other options list operational artifacts that awareness is not defined around.
-
A. The trend across campaigns is the evidence: the click rate fell while the report rate rose, which is behavior moving in the intended direction and reporting quality improving. A nonzero click rate is not itself a failure (option B), simulations are a standard behavioral measure when analyzed as a trend (option C), and rising reported incidents reflect better reporting, not program failure (option D).
-
B. Personnel transfer controls such as NIST SP 800-53 PS-5 and ISO/IEC 27002:2022 control 6.5 require access rights to be re-reviewed and re-scoped when a person’s role changes, with old privileges removed and new ones granted on a need-to-know basis, and contractor access retired at project end. Waiting for the annual review (option A) leaves ghost access live for months, and the other options change the wrong thing.
Policies, people, and the program on one page
When the details blur, hold the loops. The document loop: policy sets direction, standards and baselines bind with specifics, guidelines recommend, procedures execute, and authority flows down, so approval sits high and review runs at least annually and after material change. The employment loop: position risk designation and screening before hire, agreements and onboarding at hire, least privilege, separation of duties, job rotation, and mandatory vacation during employment, access re-scoping at transfer, and revocation at termination, with contractor personnel held to the same discipline through contract and every phase leaving records. The attention loop: awareness focuses attention and changes behavior, training builds skills, education builds specialists, the program starts at onboarding, refreshes at least annually, layers role-based training where the risk is highest, and is measured by behavior over time: click rates, report rates, assessment scores, and the trend of human-error incidents.
One sentence carries the whole chapter into the exam room: the security program is written before it is installed, so the person who controls the documents, the personnel rules, and the attention of the workforce controls the program. Chapter 7 closes Domain 1 with the practice test, twenty-five questions that reach back through governance, risk, continuity, and this chapter, and it is where the vocabulary you have built over the last four chapters becomes exam performance.
Continue reading
Full table of contents