A security manager is updating the organization's security awareness program. A proposal is made to postpone including training on artificial intelligence (AI) security risks, arguing that the technology is not yet mature and its threats are not fully defined. What is the MOST sound security principle to apply in this situation?
AI security training should only be provided to technical staff in the IT and security departments until the risks are standardized.
Training on emerging threats like AI should be included proactively, with content reviewed and updated periodically as the technology and its related risks evolve.
The security awareness program should focus only on established and well-documented threats to maximize the effective use of limited training resources.
Delaying the training is prudent, as covering immature technologies could lead to confusion and training fatigue among employees.
The correct approach is to proactively include training on emerging threats like AI and to commit to regular updates. Security awareness programs must be dynamic and adapt to the evolving threat landscape to remain effective. Waiting for a technology to mature or for threats to become "fully defined" exposes the organization to significant and preventable risks. The CISSP curriculum, along with frameworks like those from NIST, emphasizes the importance of periodic content review and incorporating topics on emerging technologies to ensure the workforce is prepared for current and future threats. While resource allocation and avoiding confusion are valid concerns, they are secondary to the primary responsibility of protecting the organization through timely and relevant awareness training.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are some specific security challenges associated with AI?
Open an interactive chat with Bash
How can organizations keep their security awareness programs updated with emerging technologies?
Open an interactive chat with Bash
What role does the CISSP framework play in security awareness programs?
Open an interactive chat with Bash
ISC2 CISSP
Security and Risk Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access