CISA Certified Information Systems Auditor – Question0816

An organization implemented a mandatory information security awareness training program a year ago. What is the BEST way to determine its effectiveness?

A.
Analyze responses from an employee survey on training satisfaction.
B. Analyze results from training completion reports.
C. Analyze results of a social engineering test.
D. Analyze findings from previous audit reports.

Correct Answer: C