A department head proposes 'sending one cautionary email' as the entire security awareness effort for the year. What should the CISO require instead?
Select an answer to reveal the explanation.
Short Explanation
One email isn’t a program—it’s a shrug with a subject line. Build the real thing: plan it, run it, measure it, improve it.
Full Explanation
Security awareness requires program development and execution: defined objectives, audiences, content, delivery methods, scheduling, metrics, and continuous improvement. A single cautionary email lacks the structure and recurrence expected of an awareness program. Municipal CISOs should insist on a managed lifecycle rather than ad hoc messaging.