Security+Program management
Security awareness
Outline only. Awareness is a recurring control aimed at human vectors, not a single annual video.
8 min read · Outline, not a finished note
Outline. This module is on the map so you can track it. The page below is a writing checklist, not finished study material.
Objectives
- Separate awareness, training, and policy
- Tie phishing recognition to the threat-vector note
TODO
Do not include phishing kits or lure-writing advice.
Checklist
- Awareness means people can recognize and report. Training means they can perform a task. A policy tells them the requirement. The exam distinguishes the three.
- Useful topics later: reporting a suspicious message, handling data by classification, tailgating, and clean-desk or screen-lock habits.
- Measure something other than attendance. Repeat behavior, such as reports of suspicious mail, is closer to the point.
- Awareness does not replace technical controls. It is one layer. A user who reports a prompt still needs MFA that resists fatigue, which is the BSCP MFA note.
- Executives and privileged users need a sharper version, because their accounts are worth more.