Skip to content
Jon MarienStudy Desk

Security+Program management

Security awareness

Outline only. Awareness is a recurring control aimed at human vectors, not a single annual video.

8 min read · Outline, not a finished note

Outline. This module is on the map so you can track it. The page below is a writing checklist, not finished study material.

Objectives

  • Separate awareness, training, and policy
  • Tie phishing recognition to the threat-vector note
On this page
  1. TODO
  2. Checklist

TODO

Do not include phishing kits or lure-writing advice.

Checklist

  • Awareness means people can recognize and report. Training means they can perform a task. A policy tells them the requirement. The exam distinguishes the three.
  • Useful topics later: reporting a suspicious message, handling data by classification, tailgating, and clean-desk or screen-lock habits.
  • Measure something other than attendance. Repeat behavior, such as reports of suspicious mail, is closer to the point.
  • Awareness does not replace technical controls. It is one layer. A user who reports a prompt still needs MFA that resists fatigue, which is the BSCP MFA note.
  • Executives and privileged users need a sharper version, because their accounts are worth more.

More on this track