09. Exercise: Championing Security
Exercise: Championing Security
Answer the following scenario:
QUESTION:
An essential part of the Governance professional's role is to participate in end-user or employee security training efforts. Phishing campaigns are one the most highly used attacks for bad actors when attempting to infiltrate an organization. As a result, many Governance professionals spend large amounts of their time developing training exercises in an effort to defeat phishing campaigns.
In this exercise, you have been tasked with creating an email that can be sent to all of your organization's users to train them on the pitfalls of phishing. Think about what you might say in an email to corporate users about phishing and respond below.
You should have at least two paragraphs in your e-mail where you:
- Define phishing
- Describe examples of phishing, what do they look like?
- Why is it important?
- What should you do if you suspect a phishing e-mail in your inbox?
ANSWER:
Communicating the importance of phishing is very important to ensure that all employees are aware of taking it seriously and the impact it could have on their information, as well as the company's sensitive information.