Which of the following is the MOST important information to be communicated during security awareness training?
Correct Answer: A
The most important information to be communicated during security awareness training is management's expectations. This will help to establish the security culture and behavior of the enterprise, and to align the staff's actions with the enterprise's objectives, policies, and standards. Management's expectations also provide the basis for measuring and evaluating the effectiveness of the security awareness program. Corporate risk profile, recent security incidents, and the current risk management capability are also important information to be communicated during security awareness training, but they are not as important as management's expectations. References = Risk and Information Systems Control Study Manual, 7th Edition, Chapter 5, Section 5.1.1.2, page 2291
1: ISACA Certified in Risk and Information Systems Control (CRISC) Exam Guide, Answer to Question
642.