1.12 Security Awareness & Training

CISSP Domain 1 · 1.12

Security Awareness & Training at a glance

Security technology alone cannot protect an organisation. People make security decisions every day — opening emails, handling information, approving payments, using passwords, reporting incidents and operating critical systems.

A security awareness, education and training programme helps people understand security risks, develop appropriate skills and make safer decisions as part of their everyday work.

💡

Awareness

Keep security risks and responsibilities visible.

What should I KNOW?
🛠️

Training

Develop practical security skills for particular activities.

What should I DO?
🎓

Education

Develop deeper understanding and professional knowledge.

WHY does it work?

Why security awareness matters

Many security controls depend on people behaving appropriately.

Employees may encounter:

Phishing Social Engineering Sensitive Data Suspicious Links Passwords AI Tools Physical Security Removable Media Security Incidents Fraud Attempts
Example

An organisation deploys sophisticated email filtering.

A convincing phishing message still reaches an employee and asks them to approve a fraudulent payment.

Technology reduces the risk, but the employee's ability to recognise and report the attack remains important.
The objective is not simply "complete the training"

A mature programme aims to influence real behaviour and create a culture where people understand their security responsibilities and know how to act when something suspicious occurs.

1 Awareness vs Training vs Education Three related but different learning goals

Security Awareness

Awareness focuses attention on security and helps people recognise important risks and responsibilities.

Awareness example

A short campaign reminds employees how to recognise suspicious QR codes and where to report them.

Security Training

Training develops practical knowledge and skills needed to perform security-related tasks correctly.

Training example

Service-desk staff learn how to verify a caller's identity before resetting an account.

Security Education

Education develops broader and deeper understanding that may support professional judgement, analysis and future security responsibilities.

Education example

A security architect studies cryptography, risk management and secure architecture so they can evaluate different design approaches.

Easy distinction

Awareness Recognise the ISSUE
Training Learn the SKILL
Education Understand the CONCEPT

Know it. Do it. Understand it.

Security Learning Programme lifecycle

🎯 Identify Needs → What behaviour or knowledge needs improvement?
👥 Understand Audience → Who needs to learn it?
📝 Design → What learning method will work?
🚀 Deliver → Provide awareness, training or education
📊 Measure → Did knowledge or behaviour improve?
🔄 Improve → What should change next time?
2 Building the Programme Start with risk and learning needs

Security learning should reflect the organisation's actual risks, technologies, workforce and operating environment.

Useful inputs include:

Risk Assessments Security Incidents Audit Findings Phishing Results New Technology Policy Changes Regulation Threat Intelligence
Example

An organisation experiences several incidents involving employees entering credentials into fake Microsoft 365 login pages.

Rather than adding another generic annual security module, the organisation creates targeted learning around authentication phishing, browser indicators and reporting.

Training is addressing an observed organisational risk.
Risk-based learning

Security training should help reduce relevant organisational risk rather than existing only to satisfy a compliance checkbox.

3 Understand the Audience Different roles face different risks

Not everyone in an organisation requires exactly the same security training.

All Employees

Basic security awareness, phishing, information handling, incident reporting and acceptable use.

Developers

Secure coding, software supply chain, secrets management and application-security practices.

Administrators

Privileged access, secure configuration, logging and operational security.

Finance Staff

Fraud, payment manipulation, business-email compromise and verification procedures.

Executives

Targeted social engineering, organisational risk, crisis response and high-value information.

Security Teams

Advanced technical, governance, risk and incident-response skills.

HR

Personal data, insider-risk indicators and personnel-security processes.

Contractors

Relevant organisational security policies and access responsibilities.

Role-based training

General awareness provides a security foundation, while role-based training addresses risks specific to someone's responsibilities.

📅 When should training occur? Learning should not happen only once a year
Onboarding

Establish security expectations when people join.

Periodic

Refresh important knowledge and introduce updated risks.

Role Change

Provide training when responsibilities or privileges change.

Technology Change

Explain security implications of new systems and services.

After Incidents

Use lessons learned to address identified knowledge gaps.

Emerging Threats

Provide timely awareness when new attack techniques become relevant.

Example

The organisation introduces generative AI tools for employees.

Rather than waiting until the next annual training cycle, employees receive targeted guidance about confidential data, approved services and appropriate AI use before rollout.

4 Awareness and Training Methods Use multiple ways to reinforce security

Security awareness does not need to rely entirely on long online courses.

Organisations can use multiple techniques:

Short Videos Interactive Training Phishing Simulations Workshops Posters Newsletters Quizzes Security Champions Gamification Tabletop Exercises Micro-Learning
Different methods serve different purposes

A five-minute reminder may be useful for awareness.

A developer learning secure coding may require detailed practical training instead.

5 Social Engineering Awareness Attack the human rather than the technology

What is social engineering?

Social engineering uses deception or manipulation to persuade someone to disclose information, provide access or perform an action that benefits the attacker.

Phishing

Fraudulent messages attempt to make recipients reveal information or perform unsafe actions.

Spear Phishing

More targeted phishing designed for a particular individual or group.

Vishing

Social engineering performed through voice calls.

Smishing

Phishing delivered through SMS or messaging.

Pretexting

The attacker invents a believable scenario to obtain information or action.

Impersonation

Pretending to be a trusted employee, supplier or authority.

Baiting

Offering something attractive to encourage unsafe behaviour.

Tailgating

Following an authorised person into a restricted physical area.

Social engineering exploits trust

Attackers may exploit urgency, fear, authority, curiosity, helpfulness or familiarity rather than a software vulnerability.

🚩 Social Engineering warning signs Help users recognise suspicious situations
Urgency

"Do this immediately or your account will be disabled."

Authority

"The CEO needs this payment approved now."

Secrecy

"Don't tell anyone else about this request."

Credential request

"Verify your password using this link."

Unexpected attachment

A document arrives without expected context.

Unusual payment request

Bank details unexpectedly change.

Bypassing process

Someone asks you to ignore normal verification procedures.

Teach a response, not only recognition

Employees should know exactly how to verify suspicious requests and where to report them.

6 Phishing Awareness and Simulations Practice recognising realistic attacks

Simulated phishing campaigns can provide employees with practical experience recognising suspicious messages in a controlled environment.

A useful programme may assess:

Reporting Link Interaction Credential Submission Response Time Repeated Behaviour Scenario Difficulty
Example

Employees receive a simulated message claiming that their cloud account will expire unless they log in immediately.

Employees who identify the message can report it using the organisation's normal phishing-reporting process.

Do not judge the programme using one number alone

A phishing click rate can provide useful information, but the organisation should consider context, scenario difficulty, reporting behaviour and longer-term trends when evaluating effectiveness.

📣 Build a Reporting Culture People should know how — and feel able — to report

Awareness should make reporting security concerns simple and familiar.

Employees may need to report:

Phishing Lost Device Suspicious Login Data Exposure Malware Physical Security Issue Social Engineering Policy Violation
Example

An employee accidentally enters their password into a phishing page.

They realise the mistake thirty seconds later.

Rapid reporting allows security teams to reset credentials, invalidate sessions and investigate the attack quickly.
Reporting speed matters

Training should tell people what to do after a mistake, not only how to avoid making one.

7 Security Champions Extend security knowledge into the wider organisation

Security champions are individuals outside the central security team who help promote good security practices within their own teams or communities.

A security champion might:

  • share relevant security information;
  • encourage secure practices;
  • help colleagues find security guidance;
  • raise security questions during projects;
  • help connect teams with security specialists;
  • promote awareness campaigns;
  • provide feedback about local security challenges.
Example

Each software-development squad has a developer who receives additional application-security training and acts as a security champion.

The champion helps bring security thinking into day-to-day development discussions.

Champions do not replace security specialists

They help distribute security awareness and create stronger links between specialist security teams and the wider organisation.

8 Gamification Make learning more engaging

Gamification introduces game-like elements into security learning to increase participation and engagement.

Points Challenges Badges Quizzes Competitions Leaderboards Capture the Flag Scenario Games
Example

Development teams compete in a secure-coding challenge where they identify vulnerabilities in a deliberately insecure application.

Participants earn points for identifying and correctly explaining each vulnerability.

Gamification is a method, not the objective

The game should support useful learning and behaviour rather than becoming an activity that people complete without understanding the security lesson.

🌱 Security Culture Move from rules toward everyday behaviour

A strong security culture exists when secure behaviour becomes a normal part of how people work rather than something considered only during annual training.

Leadership

Managers demonstrate that security is genuinely important.

Clear Expectations

People understand what is expected of them.

Accessible Guidance

Security advice is easy to find and understand.

Reporting

People report suspicious activity quickly.

Practical Controls

Secure behaviour is made easy rather than unnecessarily difficult.

Continuous Learning

Relevant security learning occurs throughout the year.

Culture difference

In one organisation, an employee receiving a suspicious request thinks: "Security isn't my job."

In another, the employee thinks: "This doesn't look right — I'll report it."

Awareness programmes should help move organisations toward the second behaviour.
9 Emerging Technology and Trends Training content must evolve

Security awareness content should be periodically reviewed as technology and attacker techniques change.

The current CISSP outline specifically highlights areas such as:

Artificial Intelligence Cryptocurrency Blockchain

🤖 Artificial Intelligence

Employees may need guidance on appropriate use of generative AI services.

Topics might include:

  • handling confidential information;
  • approved and unapproved AI services;
  • verification of AI-generated output;
  • AI-assisted phishing and impersonation;
  • deepfake or synthetic-media awareness;
  • organisation-specific AI policies.

₿ Cryptocurrency

Relevant awareness topics may include cryptocurrency-related fraud, ransomware payment demands, wallet scams and social-engineering campaigns.

⛓️ Blockchain

Where blockchain technologies are used, relevant personnel may need to understand associated security responsibilities such as protecting keys and recognising fraudulent transactions or services.

Do not teach yesterday's threat landscape forever

A security awareness programme should evolve as the organisation's technologies, risks and attacker techniques change.

🎭 Modern Impersonation and Deepfakes Old social-engineering principles with new technology

New technologies can make traditional social engineering more convincing.

Example

A finance employee receives a voice message that appears to come from a senior executive requesting an urgent transfer.

The voice may sound completely genuine.

Employees should rely on approved verification processes rather than trusting a request simply because a voice, image or message appears authentic.
Security principle survives technological change

Verify sensitive requests using trusted processes and independent channels.

📜 Training should support policy People need to understand organisational requirements

Security awareness helps turn written policies into practical behaviour.

Acceptable Use

How organisational technology may be used.

Information Handling

How sensitive data should be protected.

Password / Authentication

How authentication requirements should be followed.

Incident Reporting

When and how security events should be reported.

Remote Working

Security expectations outside normal offices.

AI Usage

Which AI tools and information-handling practices are permitted.

Policy tells people the rule

Awareness and training help them understand what the rule means in practical situations.

👍 Make secure behaviour easier Training cannot fix unusable security processes

If organisational security procedures are unnecessarily difficult, people may look for shortcuts.

Example

Employees are told never to use consumer file-sharing services.

However, the organisation provides no approved method for sending large files to customers.

Awareness alone is unlikely to solve the problem. Employees also need a practical secure alternative.
People, process and technology work together

Security education should support effective controls, not compensate indefinitely for badly designed processes.

10 Evaluate Programme Effectiveness Did the learning actually work?

The current CISSP objective explicitly requires understanding programme effectiveness evaluation.

Organisations therefore need to measure more than whether employees clicked "Complete".

Possible measurements include:

Completion

Did the intended audience complete required learning?

Knowledge

Can learners demonstrate understanding?

Behaviour

Has real security behaviour changed?

Reporting

Are suspicious events being reported appropriately?

Incident Trends

Are relevant human-related incidents changing over time?

Role Competency

Can personnel perform security-sensitive responsibilities correctly?

📊 Useful Security Awareness Metrics Measure outcomes, not just activity
Activity metric

"99% of employees completed annual security training."

Knowledge metric

"Employees correctly answered 90% of questions relating to confidential-data handling."

Behaviour metric

"The proportion of simulated phishing messages reported by employees increased over successive campaigns."

Risk metric

"Incidents caused by users entering credentials into phishing sites declined following targeted authentication-phishing training."

Completion ≠ effectiveness

High completion proves that training was delivered.

It does not by itself prove that people learned anything or changed their behaviour.

🎣 Interpreting Phishing Metrics Context matters

Phishing simulation results can provide useful information, but a single click rate should not automatically be treated as the complete measure of security awareness.

Consider:

Scenario Difficulty Reporting Rate Repeat Behaviour Credential Entry Department Trends Time Trends
Example

Campaign A has a 5% click rate.

Campaign B has a 15% click rate.

It would be tempting to conclude immediately that security awareness became worse.

But Campaign B may have been significantly more convincing than Campaign A, so scenario difficulty should also be considered.

Awareness improvement cycle

📊 Measure → What are people struggling with?
🔍 Analyse → Why is the behaviour occurring?
🎓 Educate → Provide targeted learning
🛠️ Improve Controls → Make secure behaviour easier
📈 Re-measure → Did behaviour improve?
11 Periodic Content Review Keep the programme relevant

Training content should be reviewed periodically and when significant changes occur.

Review triggers may include:

New Threats

Attackers begin using new techniques.

New Technology

Employees begin using different systems or services.

Security Incidents

Events reveal gaps in knowledge or behaviour.

Policy Changes

Organisational expectations change.

Legal / Regulatory Change

New obligations require different behaviour.

Measurement Results

Metrics show particular topics require more attention.

Outdated content

Annual awareness training still focuses heavily on avoiding unknown USB drives but contains nothing about cloud sharing, MFA phishing, QR-code phishing or generative AI.

The programme may no longer reflect how employees actually work or how modern attacks occur.
🚨 Learn from Security Incidents Incidents reveal real learning needs

Incident investigations can identify weaknesses in awareness, procedures or role-specific training.

Example

Several help-desk employees reset accounts after attackers provide convincing but fraudulent identity information.

Investigation finds that the existing verification procedure is poorly understood.

Targeted help-desk training and improvements to the verification process may both be required.
Do not automatically assume "user error"

An incident may expose weaknesses in training, processes, technology or organisational design.

👔 Leadership and Management Security culture needs visible support

Management behaviour influences whether employees treat security requirements seriously.

Bad example

Employees are told never to share passwords.

Their manager then asks the team to share one account because creating individual accounts would take too long.

Leadership behaviour has undermined the security message.

Leadership can support awareness by:

  • following security policies themselves;
  • supporting training participation;
  • encouraging incident reporting;
  • supporting security champions;
  • providing time and resources for learning;
  • reinforcing that security supports business objectives.
🛡️ Training as a Security Control Useful, but not the answer to everything

Awareness and training can reduce risk, but organisations should not use training as a substitute for technical controls that can reasonably prevent a problem.

Weak approach

"Train employees never to accidentally email confidential data to the wrong external recipient."

Better layered approach

Provide data-handling training while also using access controls, recipient warnings, classification and DLP where appropriate.

Defense in depth includes people

Awareness should work alongside technical, administrative and physical controls.

⚠️ Common mistakes Awareness-programme assumptions that reduce effectiveness
"Everyone completed training, so the programme is effective."

Completion measures delivery, not necessarily knowledge, behaviour or risk reduction.

"Security awareness means annual e-learning."

Effective awareness can use ongoing campaigns, simulations, champions, targeted learning and other methods throughout the year.

"Everyone needs exactly the same security training."

General awareness is useful, but people with specialist or privileged responsibilities often require role-based training.

"The phishing click rate tells us everything."

Scenario difficulty, reporting behaviour and trends should also be considered.

"If somebody clicked a phishing simulation, punish them."

The primary goal of simulated phishing should be improving behaviour and reducing risk rather than creating fear around training.

"Employees should simply know better."

Secure behaviour depends on awareness, usable processes, appropriate technology and clear organisational expectations.

"Training from three years ago is still good enough."

Technology, organisational processes and attack techniques evolve. Training content should therefore be reviewed.

"AI security awareness is only relevant to technical staff."

Employees in many roles may interact with AI services or receive AI-assisted phishing, impersonation or fraudulent content.

"Security champions replace the security team."

Champions help promote security within other teams but do not replace specialist security expertise.

"Training can solve any security problem."

Where a risk can reasonably be prevented or reduced through technical or process controls, training should form part of a layered approach rather than becoming the only defence.

CISSP Exam Perspective

Think behaviour, risk and continuous improvement

CISSP questions in this area are likely to favour a structured, risk-based programme rather than treating security awareness as a once-a-year compliance exercise.

💡 Awareness clues

Recognition Security Culture Communication Campaign Reminder

🛠️ Training clues

Skill Role-Based Practice Competency Procedure

🎣 Social engineering clues

Phishing Impersonation Urgency Trust Verification

👥 Engagement clues

Security Champions Gamification Micro-Learning Participation

🔄 Review clues

Emerging Technology AI Cryptocurrency Blockchain New Threats

📊 Effectiveness clues

Metrics Behaviour Reporting Trends Improvement
📝 Practice scenarios Apply security-awareness thinking

Scenario 1

All employees have completed mandatory annual security training.

Phishing-related incidents continue increasing.

What should the organisation do?

Evaluate whether the training is producing the desired knowledge and behaviour, identify the underlying causes and adjust the programme.

Scenario 2

Developers receive the same general 20-minute security awareness course as every other employee.

Secure coding weaknesses are repeatedly discovered.

What is missing?

Appropriate role-based security training for developers.

Scenario 3

An employee receives a suspicious email appearing to come from the CEO and asking for an urgent payment.

What should awareness training encourage?

Recognise the social-engineering indicators, independently verify the request and report the suspicious message.

Scenario 4

A simulated phishing campaign has a much higher click rate than the previous campaign.

What should be considered before concluding that employees became worse at recognising phishing?

The relative difficulty and context of the different phishing scenarios.

Scenario 5

The organisation introduces generative AI tools for employees.

What should happen?

Security-learning content should be reviewed and updated to address relevant AI-related security and information-handling risks.

Scenario 6

Each development team has a developer who receives additional application-security learning and promotes secure practices within the team.

Which concept does this describe?

Security champions.

Scenario 7

Employees earn points and badges for completing interactive cybersecurity challenges.

Which awareness technique is being used?

Gamification.

Scenario 8

An employee clicks a phishing link and immediately realises the mistake.

What should the programme have taught them?

How to report the incident quickly so security teams can respond.

Scenario 9

Security training teaches employees not to use public file-sharing services, but the organisation provides no approved way to exchange large customer files.

What is the problem?

Training alone cannot compensate for the absence of a practical secure business process.

Scenario 10

Management asks for the best single measurement of awareness-programme effectiveness.

What should security explain?

Effectiveness is better evaluated using multiple measures of learning, behaviour, reporting, risk and trends rather than relying on one metric.

Scenario 11

A finance employee receives a convincing voice message from the CFO instructing them to transfer money to a new account.

What principle remains important even if the voice sounds authentic?

Independently verify sensitive requests using established trusted procedures.

Scenario 12

Training material still teaches threats from five years ago and has never been reviewed.

Which CISSP 1.12 requirement is missing?

Periodic content review to incorporate emerging technology, trends and changing risks.

Scenario 13

Security notices are written using highly technical language that non-technical employees do not understand.

What should improve?

Training and awareness should be designed for the intended audience.

Scenario 14

Phishing reports from employees increase substantially after a new awareness campaign.

Is this necessarily a bad result?

No. Increased reporting may indicate that employees are becoming better at recognising and reporting suspicious messages.

Security Awareness thinking flow

⚠️ Risk → What behaviour creates exposure?
👥 Audience → Who needs to change?
🎓 Learning → What do they need to know or do?
🚀 Delivery → How will we teach it?
📊 Measure → Did behaviour change?
🔄 Improve → What should we change?

Quick memory aid

Awareness KNOW the risk
Training DO the right thing
Education UNDERSTAND the subject
Champions SPREAD security knowledge
Gamification ENGAGE learners
Metrics Did behaviour IMPROVE?

Know. Practice. Measure. Improve.

Social Engineering memory aid

Urgency "Do it NOW"
Authority "The CEO said so"
Fear "Your account will be closed"
Curiosity "Look what happened!"
Secrecy "Don't tell anyone"
Verification STOP and CHECK independently

Don't trust pressure. Verify the request.

Programme effectiveness memory aid

Completion Did they ATTEND?
Knowledge Did they LEARN?
Behaviour Did they CHANGE?
Risk Did exposure REDUCE?
Improvement What do we do NEXT?

Completion is the beginning, not the result.

Key takeaways

Security awareness, training and education help people understand security risk and perform their responsibilities securely.

Awareness focuses attention on security issues and expected behaviour.

Training develops practical security skills.

Education develops deeper understanding and professional knowledge.

Security learning should reflect the organisation's actual risks, technologies, incidents and workforce.

Different roles require different levels and types of security learning.

Social-engineering awareness should help users recognise attacks such as phishing, impersonation and pretexting and know how to respond.

Phishing simulations can provide useful practical learning, but their results should be interpreted in context rather than relying only on a single click-rate metric.

Security champions can extend security knowledge and engagement into teams outside the central security function.

Gamification can increase engagement when game mechanics support genuine learning objectives.

Awareness content should be periodically reviewed to reflect changes in threats, business processes and technologies.

The current CISSP outline specifically highlights emerging areas such as artificial intelligence, cryptocurrency and blockchain.

Security programmes should evaluate effectiveness using relevant measures of knowledge, behaviour, reporting and risk.

Training completion alone does not demonstrate that behaviour changed.

Security awareness works best when secure behaviour is supported by usable processes and appropriate technical controls.

Incidents, assessments and programme metrics should feed back into future learning.

Most importantly: the goal is not to make people pass a training module — it is to help them make better security decisions when it actually matters.

CISSP Domain 1 Complete

Security and Risk Management

You have reached the end of CyberPrepHub's Security and Risk Management learning section.

Domain 1 connects security technology with ethics, governance, law, business continuity, people, risk and organisational decision-making.

Professional Ethics Security Concepts Governance Law & Privacy Investigations Policies Business Continuity Personnel Security Risk Management Threat Modeling Supply Chain Risk Security Awareness
The big Domain 1 lesson

Cybersecurity is not simply about choosing technical controls.

Effective security means understanding the organisation, its people, objectives, obligations and risks — and using that understanding to make informed security decisions.

📚 Sources & Further Reading Authoritative references