A program lives in its operation. Part B runs it day to day: building a security culture, managing third-party and supply-chain risk, operating security, measuring value, and improving continuously.
Part A established the program; Part B keeps it alive and effective. The security manager shapes the human layer through awareness and culture, governs the growing third-party and supply-chain attack surface, oversees security operations, proves value with metrics, and drives continuous improvement. The exam rewards the manager who treats people and suppliers as first-class risks and who measures the program in business terms rather than tool output.
Learning Objectives
By the end of this lesson you will be able to…
Design awareness, training, and culture programs that change behavior. Bloom: Create
Govern third-party and supply-chain risk through due diligence, contracts, and ongoing oversight. Bloom: Apply
Oversee security operations — monitoring, vulnerability and configuration management, and IAM. Bloom: Evaluate
Define program metrics that communicate value and effectiveness to leadership. Bloom: Remember
Drive continuous improvement and integrate security into the delivery lifecycle. Bloom: Apply
Key Terms
Program operations vocabulary
👈 Tap a card to flip it. People, suppliers, operations, metrics — the working program.
Lesson Content
Study the material
1
Awareness, Training & Culture
Objective 1 · awareness and culture
People are both the largest attack surface and the strongest control. The manager’s job is to move the organization from awareness (attention) to behavior to culture, with role-appropriate content and reinforcement — not a once-a-year slide deck.
Awareness shifts behavior; training builds skills; education builds understanding — deliver all three by role.
Role-based content: developers, executives, finance, and admins each face different risks and need tailored training.
Phishing simulations measure and reinforce — track trends, not just a single score.
Culture is the goal: secure behavior becomes the default, sustained by tone at the top.
💡 Exam TipIf a phishing click-rate keeps rising despite annual training, the issue is program effectiveness — revise content, frequency, and reinforcement. Punishing employees or blocking all email is not the CISM answer.
Try it — what awareness buys you (and where it stops)
Awareness is a control with a cost curve like any other. Fund training and the phishing click-rate falls — fast at first, then with diminishing returns toward a floor you can’t train away. That floor is why culture and awareness are paired with technical controls, never relied on alone.
Interactive · adjust & explore
Your awareness program
Untrained, ~30% of people click a phish.
$60,000
Spend on content, simulations, and reinforcement.
1,000
More people dilutes the same budget per head.
12
How often each person is targeted.
The human risk
Phishing click rate
—
Spend / employee
—
Risky clicks / year
—
Likely incidents / year
—
——Fund the program and watch the click rate fall.
Click rate vs. training spend
Click rate falls with spend per employee — steeply at first, then flattening toward a floor awareness can’t remove. Your operating point (●) is at your current per-head spend.
Click rate Your operating point Floor (can’t train away)
🔎 In practice
The curve makes the management case: awareness is the highest-ROI control at low spend, but it asymptotes — you can’t train the last few percent of clicks away. A mature program spends to the knee of the curve and then relies on phishing-resistant MFA, email filtering, and fast response for the residual. And per the exam tip: a rising click-rate is a program-effectiveness problem, not a reason to punish users.
📚
Explore furtherSocial Engineering and Social Engineering Tactics — interactive modules on the human-layer attacks your awareness program must defend against.
Outsourcing and cloud move work outside the organization — but never the accountability. Third-party risk is governed across the whole relationship lifecycle, and the data owner remains responsible no matter who processes the data.
Due diligence before engagement (questionnaires, SOC 2 Type II, audits) and periodic re-assessment after.
Contracts carry the controls: right-to-audit, SLAs, breach-notification timelines, data handling, and return/destruction on exit.
Cloud shared responsibility: the provider secures the platform per the service model; the customer always owns its data and access.
Fourth-party and concentration risk: understand your vendors’ critical subcontractors and single points of failure.
🔎 In practice
‘We moved it to the cloud, so the provider is responsible’ is a trap. Under shared responsibility the customer still owns data classification, access, and configuration — most cloud breaches stem from customer-side misconfiguration, not the provider.
3
Security Operations
Objective 3 · security operations
Operations is where the program runs continuously. The manager oversees these functions and ensures they are measured and improving — without doing the hands-on work personally.
Monitoring/SIEM and threat detection give visibility; coverage and tuning matter more than tool count.
Vulnerability management prioritizes by business risk (asset value + exploitability), not raw severity scores alone.
Assessment vs. testing — and which to commission: a vulnerability assessment scans broadly and does not exploit, giving wide coverage of known weaknesses; a penetration test is narrower but exploits them to prove real-world impact and attack paths. Use VA for routine, wide coverage; commission a pen test to validate exploitability or satisfy a compliance/assurance requirement.
Configuration and change management keep systems to baselines and prevent unauthorized drift.
IAM operations — provisioning, periodic access reviews, and timely deprovisioning — enforce least privilege over time.
💡 Exam TipVulnerability questions reward risk-based prioritization: a medium-severity flaw on a critical, internet-facing system may outrank a ‘critical’ CVSS score on an isolated test box. Context, not the number alone, sets priority.
📚
Explore furtherPenetration Testing and Configuration Management — interactive modules on testing the program and on the configuration and change discipline that keeps it to baseline.
A program that cannot show its value loses funding. Metrics prove effectiveness, justify investment, and guide decisions — but only if they map to objectives and are reported in language the business understands.
Tie metrics to control objectives and risk (KGI/KPI/KRI), not to raw activity counts.
Report trends and business impact to leadership — reducing risk and enabling the business — not tool dashboards.
Use a balanced view (value, risk, compliance, operational performance), avoiding vanity metrics.
Maturity assessments track whether processes are improving over time.
🔎 In practice
Reporting ‘we blocked 4 million emails’ tells the board nothing. ‘Phishing susceptibility fell from 18% to 6%, cutting our most likely breach path’ ties the program to risk and value — that is a CISM-grade metric.
5
Continuous Improvement
Objective 5 · continuous improvement
The program is never finished. Threats, technology, and the business change, so the manager institutionalizes improvement rather than treating security as a set of one-time projects.
Plan-Do-Check-Act: the ISO 27001 cycle — implement, measure, and refine continually.
Lessons learned from incidents, audits, and tests feed back into controls and strategy.
Integrate security into delivery (secure SDLC / DevSecOps) so controls are built in, not bolted on.
Re-baseline against the strategy and gap analysis as objectives and risk evolve.
💡 Exam TipWhen asked how to keep a program effective over time, the answer is a continuous-improvement cycle (PDCA) fed by metrics and lessons learned — not a bigger one-time project or a new tool purchase.
Scored Knowledge Check
Test your program-operations judgment
Eight questions on people, suppliers, operations, and metrics. Manage and measure; don’t configure.