1/26
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is separation of duties?
Splitting a critical process so no single person can complete it alone. Prevents one individual from committing and concealing fraud.
What is job rotation?
Periodically moving staff between roles. Exposes irregularities that a permanent occupant could hide and cross-trains the team.
What is mandatory vacation?
Requiring employees in sensitive roles to take consecutive time off, so schemes requiring ongoing concealment surface while they're away.
What is least privilege as a personnel policy?
Granting each employee only the access their role requires, reviewed when they change roles so rights don't accumulate.
What is a clean desk policy?
Requiring sensitive materials be secured when unattended, preventing casual observation, theft, or photography of documents and credentials.
What is a background check?
Pre-employment verification of identity, employment history, credentials, and criminal record, scaled to the sensitivity of the role.
What are onboarding security responsibilities?
Signing the AUP and NDA, provisioning least-privilege access, issuing equipment, and completing initial security awareness training.
What are offboarding security responsibilities?
Immediately disabling accounts and revoking access, recovering assets and credentials, conducting an exit interview, and confirming NDA obligations continue.
What is an acceptable use policy (AUP)?
Defines permitted and prohibited use of company systems, networks, and data. Signed by employees, and the basis for enforcement action.
What is a social media policy?
Governs what employees may disclose publicly about the organization, limiting information useful for social engineering and reconnaissance.
What is a remote and hybrid work policy?
Sets security requirements for working outside the office — approved devices, VPN use, home network standards, and physical privacy expectations.
What is security awareness training?
Ongoing education teaching employees to recognize and respond to threats, turning the workforce from the weakest link into a detection layer.
What is role-based security training?
Tailoring training content to job function — developers get secure coding, finance gets BEC and wire fraud, executives get whaling awareness.
What is phishing?
A social engineering attack using fraudulent messages to trick recipients into revealing credentials, sending money, or executing malware.
What is spear phishing?
Phishing targeted at a specific individual or group using researched personal details, making it far more convincing than bulk phishing.
What is whaling?
Spear phishing aimed at executives and other high-value targets who hold broad authority and access.
What are vishing, smishing, and pharming?
Vishing uses voice calls. Smishing uses SMS. Pharming redirects users to a fraudulent site through DNS manipulation rather than a lure.
What is business email compromise (BEC)?
An attacker impersonates or compromises an executive or vendor account to authorize fraudulent payments or data transfers. Often uses no malware at all.
What are common indicators of a phishing message?
Urgency and pressure, unexpected requests, mismatched sender and reply-to addresses, hovering links that don't match their text, unexpected attachments, and requests to bypass normal process.
What is a phishing simulation campaign?
Sending controlled fake phishing emails to employees to measure click rates and reporting rates, identifying who needs additional training.
What is anomalous behavior recognition training?
Teaching users to notice risky, unexpected, or unintentional behavior — their own and others' — such as unusual requests, tailgating, or a coworker's account acting oddly.
Why is user reporting critical to security awareness?
Users often detect attacks before tools do. An easy, blame-free reporting path converts individual detections into organization-wide defense.
Why should reporting be non-punitive?
If users fear blame, they hide mistakes, which delays response. Rewarding reports — including of one's own errors — surfaces incidents faster.
What metrics are used to monitor security awareness effectiveness?
Phishing simulation click and report rates, training completion rates, time to report, and incident volume traced to user behavior.
What is the development phase of a security awareness program?
Building the program: assessing risks and gaps, defining objectives and audiences, and creating role-appropriate content and delivery methods.
What is the execution phase of a security awareness program?
Delivering the training, running simulations and campaigns, measuring results, reporting to stakeholders, and revising content based on what the metrics show.
Under the General Data Protection Regulation (GDPR), how soon must an organization report a breach of personal data?
72 hours