Day 3 — Afternoon · Domain 3 (33%)

Security Program — Part B

A program lives in its operation. Part B runs it day to day: building a security culture, managing third-party and supply-chain risk, operating security, measuring value, and improving continuously.

Session: Afternoon, Day 3 Duration: ~3 hrs Exam Weight: 33% (Domain 3) Knowledge Check: 8 Questions

Overview

Operate the program, measure it, improve it

Part A established the program; Part B keeps it alive and effective. The security manager shapes the human layer through awareness and culture, governs the growing third-party and supply-chain attack surface, oversees security operations, proves value with metrics, and drives continuous improvement. The exam rewards the manager who treats people and suppliers as first-class risks and who measures the program in business terms rather than tool output.

Learning Objectives

By the end of this lesson you will be able to…

Key Terms

Program operations vocabulary

👈 Tap a card to flip it. People, suppliers, operations, metrics — the working program.

Lesson Content

Study the material

1

Awareness, Training & Culture

Objective 1 · awareness and culture

People are both the largest attack surface and the strongest control. The manager’s job is to move the organization from awareness (attention) to behavior to culture, with role-appropriate content and reinforcement — not a once-a-year slide deck.

  • Awareness shifts behavior; training builds skills; education builds understanding — deliver all three by role.
  • Role-based content: developers, executives, finance, and admins each face different risks and need tailored training.
  • Phishing simulations measure and reinforce — track trends, not just a single score.
  • Culture is the goal: secure behavior becomes the default, sustained by tone at the top.
💡 Exam TipIf a phishing click-rate keeps rising despite annual training, the issue is program effectiveness — revise content, frequency, and reinforcement. Punishing employees or blocking all email is not the CISM answer.

Try it — what awareness buys you (and where it stops)

Awareness is a control with a cost curve like any other. Fund training and the phishing click-rate falls — fast at first, then with diminishing returns toward a floor you can’t train away. That floor is why culture and awareness are paired with technical controls, never relied on alone.

Interactive · adjust & explore
Your awareness program

Untrained, ~30% of people click a phish.

$60,000
Spend on content, simulations, and reinforcement.
1,000
More people dilutes the same budget per head.
12
How often each person is targeted.
The human risk
Phishing click rate
Spend / employee
Risky clicks / year
Likely incidents / year
Fund the program and watch the click rate fall.
Click rate vs. training spend

Click rate falls with spend per employee — steeply at first, then flattening toward a floor awareness can’t remove. Your operating point (●) is at your current per-head spend.

Click rate Your operating point Floor (can’t train away)
🔎 In practice

The curve makes the management case: awareness is the highest-ROI control at low spend, but it asymptotes — you can’t train the last few percent of clicks away. A mature program spends to the knee of the curve and then relies on phishing-resistant MFA, email filtering, and fast response for the residual. And per the exam tip: a rising click-rate is a program-effectiveness problem, not a reason to punish users.

2

Third-Party & Supply-Chain Risk

Objective 2 · third-party risk

Outsourcing and cloud move work outside the organization — but never the accountability. Third-party risk is governed across the whole relationship lifecycle, and the data owner remains responsible no matter who processes the data.

  • Due diligence before engagement (questionnaires, SOC 2 Type II, audits) and periodic re-assessment after.
  • Contracts carry the controls: right-to-audit, SLAs, breach-notification timelines, data handling, and return/destruction on exit.
  • Cloud shared responsibility: the provider secures the platform per the service model; the customer always owns its data and access.
  • Fourth-party and concentration risk: understand your vendors’ critical subcontractors and single points of failure.
🔎 In practice

‘We moved it to the cloud, so the provider is responsible’ is a trap. Under shared responsibility the customer still owns data classification, access, and configuration — most cloud breaches stem from customer-side misconfiguration, not the provider.

3

Security Operations

Objective 3 · security operations

Operations is where the program runs continuously. The manager oversees these functions and ensures they are measured and improving — without doing the hands-on work personally.

  • Monitoring/SIEM and threat detection give visibility; coverage and tuning matter more than tool count.
  • Vulnerability management prioritizes by business risk (asset value + exploitability), not raw severity scores alone.
  • Assessment vs. testing — and which to commission: a vulnerability assessment scans broadly and does not exploit, giving wide coverage of known weaknesses; a penetration test is narrower but exploits them to prove real-world impact and attack paths. Use VA for routine, wide coverage; commission a pen test to validate exploitability or satisfy a compliance/assurance requirement.
  • Configuration and change management keep systems to baselines and prevent unauthorized drift.
  • IAM operations — provisioning, periodic access reviews, and timely deprovisioning — enforce least privilege over time.
💡 Exam TipVulnerability questions reward risk-based prioritization: a medium-severity flaw on a critical, internet-facing system may outrank a ‘critical’ CVSS score on an isolated test box. Context, not the number alone, sets priority.
4

Program Metrics & Reporting

Objective 4 · program metrics

A program that cannot show its value loses funding. Metrics prove effectiveness, justify investment, and guide decisions — but only if they map to objectives and are reported in language the business understands.

  • Tie metrics to control objectives and risk (KGI/KPI/KRI), not to raw activity counts.
  • Report trends and business impact to leadership — reducing risk and enabling the business — not tool dashboards.
  • Use a balanced view (value, risk, compliance, operational performance), avoiding vanity metrics.
  • Maturity assessments track whether processes are improving over time.
🔎 In practice

Reporting ‘we blocked 4 million emails’ tells the board nothing. ‘Phishing susceptibility fell from 18% to 6%, cutting our most likely breach path’ ties the program to risk and value — that is a CISM-grade metric.

5

Continuous Improvement

Objective 5 · continuous improvement

The program is never finished. Threats, technology, and the business change, so the manager institutionalizes improvement rather than treating security as a set of one-time projects.

  • Plan-Do-Check-Act: the ISO 27001 cycle — implement, measure, and refine continually.
  • Lessons learned from incidents, audits, and tests feed back into controls and strategy.
  • Integrate security into delivery (secure SDLC / DevSecOps) so controls are built in, not bolted on.
  • Re-baseline against the strategy and gap analysis as objectives and risk evolve.
💡 Exam TipWhen asked how to keep a program effective over time, the answer is a continuous-improvement cycle (PDCA) fed by metrics and lessons learned — not a bigger one-time project or a new tool purchase.

Scored Knowledge Check

Test your program-operations judgment

Eight questions on people, suppliers, operations, and metrics. Manage and measure; don’t configure.

Q1.An organization’s phishing-simulation click rate has risen over three consecutive quarters despite annual training. The BEST response is to:

Question 1 options
Correct: C. A rising click rate is a sign the awareness program is not changing behavior. The manager improves the program (content, cadence, reinforcement) rather than punishing users or blocking email outright. Why the others fall short: A disciplining clickers is punitive and ignores program effectiveness; B blocking all external email is impractical; D discontinuing simulations removes the measurement, not the problem.

Q2.After migrating data to a SaaS provider, who remains accountable for classifying and protecting that data?

Question 2 options
Correct: D. Under the shared-responsibility model, accountability for data classification, access, and configuration always stays with the customer/data owner, regardless of the service model. Why the others fall short: A the provider handles infrastructure, not accountability for the data; B a broker doesn’t assume data accountability; C accountability doesn’t hinge on contract silence — it stays with the data owner.

Q3.What should a security manager do BEFORE engaging a new critical vendor?

Question 3 options
Correct: B. Due diligence before engagement assesses the vendor’s security posture so risk can be understood and addressed in the contract. Reputation is not a substitute for assessment. Why the others fall short: A signing quickly skips assessment; C waiting for an incident is reactive; D assuming a well-known vendor is secure is unverified trust.

Q4.Two vulnerabilities are open: a ‘critical’ CVSS flaw on an isolated lab server, and a ‘medium’ flaw on an internet-facing system holding customer data. Which should be prioritized?

Question 4 options
Correct: A. Vulnerability prioritization is risk-based: exposure and asset value can make a medium-severity, internet-facing flaw far more urgent than a high score on an isolated system. Context outranks the raw number. Why the others fall short: B the CVSS score alone ignores exposure and asset value; C deferring both ignores real exposure; D treating them equally ignores context — business risk sets priority.

Q5.Which metric is MOST useful for reporting program value to the board?

Question 5 options
Correct: D. Board-level metrics tie the program to business risk and value — e.g., reduced susceptibility lowering the most likely breach path. Raw activity counts (emails blocked, alerts, rules) are not decision-useful. Why the others fall short: A emails blocked, B firewall-rule counts, and C SIEM alert volume are activity metrics — not the risk-reduction story the board needs.

Q6.The PRIMARY purpose of a right-to-audit clause in a vendor contract is to:

Question 6 options
Correct: C. A right-to-audit clause preserves the organization’s ability to assess whether the vendor’s controls are adequate — a core mechanism of ongoing third-party oversight. Why the others fall short: A it’s not about price; B it doesn’t transfer liability; D it doesn’t guarantee uptime — it preserves the ability to verify controls.

Q7.Which BEST describes how a mature program sustains effectiveness over time?

Question 7 options
Correct: B. Continuous improvement — Plan-Do-Check-Act informed by metrics and lessons learned — keeps the program effective as conditions change, rather than episodic projects or tool buying. Why the others fall short: A a single annual project isn’t sustained improvement; C buying new tools yearly isn’t a process; D outsourcing everything abdicates ownership.

Q8.Integrating security controls into the software development lifecycle (DevSecOps) PRIMARILY benefits the program by:

Question 8 options
Correct: A. Embedding security across the delivery lifecycle catches issues earlier, where they are cheaper to fix, and produces inherently more secure systems — controls are built in, not retrofitted. Why the others fall short: B DevSecOps doesn’t eliminate the security team; C it doesn’t remove testing; D it doesn’t shift all accountability to developers — it builds controls in early.