CISM Certified Information Security Manager – Question0960

A security awareness program should:

A.
present top management's perspective.
B. address details on specific exploits.
C. address specific groups and roles.
D. promote security department procedures.

Correct Answer: C

Explanation:

Explanation:
Different groups of employees have different levels of technical understanding and need awareness training that is customized to their needs; it should not be presented from a specific perspective. Specific details on technical exploits should be avoided since this may provide individuals with knowledge they might misuse or it may confuse the audience. This is also not the best forum in which to present security department procedures.