Security Awareness Training: Building a Program That Changes Behavior
Security awareness training has a reputation problem, and mostly it is deserved. An annual compliance video that everyone clicks through at 4:50 p.m. on the last day of the quarter changes nobody's behavior. CompTIA tests awareness as a program with components, cadence and metrics — not as an event. Why It Is a Control at All People are involved in the large majority of breaches, usually through phishing, credential reuse or misconfiguration. Technical controls handle what they can, but no filter catches every message and no policy engine stops someone from approving a fraudulent invoice. Awareness is the control that addresses the decision itself. It is a compensating control, not a primary one. If your answer to a phishing question is "train the users" and nothing else, the answer is incomplete. Training reduces the rate; layered technical controls handle what gets through. Program Components Security+ expects familiarity with the standard pieces: Onboardin...