Instiq
Chapter 5 · Practice (Exam B)·v1.0.0·Updated 7/9/2026·~15 min

What's changed: Initial version

5.3Security Education, Training, and Rule Operation

Key points

Learn, through concrete organizational scenarios, how to design employee education, run and evaluate targeted-attack drills, thoroughly communicate rules and procedures, handle onboarding/offboarding procedures (account issuance and privilege revocation), respond to rule violations, and raise organization-wide security awareness.

No matter how many technical countermeasures are stacked up, it is people who ultimately operate the systems. Opening a phishing email, taking confidential information out on a personal USB drive without knowing the rules, leaving a departed employee's account untouched--incidents rooted in "people and operations" never stop occurring. An information security manager must design a mechanism that not only creates rules but embeds them across the organization and continuously verifies them.

5.3.1Employee education and targeted-attack drills

  • Employee education matters most when it is not a one-time session at hiring but is repeated on a regular basis (roughly once a year or more). Rather than sticking to general lectures, covering cases that have actually happened (or could happen) at the company itself makes it easier for employees to feel personally implicated. The effectiveness of the education should be measured not just by attendance rate but by the pass rate on a comprehension test and the trend in the drill "click rate" described below.
  • A targeted-attack drill involves sending employees a simulated attack email (disguised as a fake invoice, a fake HR notice, and so on) and measuring the open rate, link-click rate, and attachment-execution rate. The goal is not to single out and punish specific employees but to understand where the organization as a whole is vulnerable and feed that back into improving the education content. Giving employees who fall for it immediate feedback, such as displaying an awareness-raising message on the spot, tends to make the lesson stick.

5.3.2Communicating rules/procedures and onboarding/offboarding procedures

  • Merely drafting rules and procedures and posting them on the intranet does not amount to thorough communication. A mechanism that lifts rules from "known" to "actually followed" is needed--confirmation of having read them (obtaining a signature or checkbox), periodic re-confirmation, and targeted reminders on the points most often violated. When rules are revised, a process of re-communicating the changes explicitly is also indispensable.
  • Onboarding/offboarding procedures: on hiring, the principle is to issue an account with only the minimum privilege necessary for the job (the principle of least privilege), and on departure, to disable the account and revoke privileges on the day of departure at the latest. On transfer, "privilege accumulation" easily occurs--adding privileges for the new department while leaving the old department's privileges intact--so periodic inventories are needed to surface unnecessary privileges.
Exam point

The staples: the purpose of a targeted-attack drill is to understand the organization's weak points and improve training, not to punish employees; a departed employee's account is disabled on the day of departure; on transfer, old privileges are surfaced through inventory and unnecessary ones are revoked; rules take hold not just by being drafted and posted but through read-confirmation and repeated training. Classic wrong answers include "disciplining an employee who fell for the drill" and "leaving an account active for a while after departure."

5.3.3Responding to violations and raising awareness

  • When a rule violation is discovered, the first step is to confirm the facts (was it intentional misconduct, or negligence from a lack of knowledge?), and then to consider, as separate matters, whether disciplinary action under work rules is warranted and what education or process improvement is needed to prevent recurrence. Focusing only on discipline while neglecting root-cause analysis makes the same kind of violation likely to recur with a different employee.
  • Raising organization-wide security awareness benefits from initiatives such as management itself leading by example in following the rules (top-level commitment), visualizing each department's drill click rate and violation count to spur improvement, and building a culture where reporting feels safe (a no-blame culture) so that even minor mistakes get shared early. Note that the harder discipline is pushed, the more reports tend to get concealed, which can actually delay discovery.

Take the annual cycle of a manufacturing company's HR and information systems department as an example of how education and rule operation connect. At the start of the fiscal year, the department runs information security training for all employees, explaining password management, handling of confidential information, and how to spot targeted-attack emails, using a real case from the company's own past--a "fake invoice email disguised as coming from a business partner." A comprehension test follows the training, and employees who fail must retake it. Six months later, a surprise targeted-attack drill found that the sales department's link-click rate was nearly three times the company-wide average. The information systems department used this result not as material to punish individual employees, but as material to design additional, targeted training for the sales department (using cases suited to a job that involves frequent email exchange with business partners). Around the same time, it came to light that an employee, "because work was piling up," had saved customer materials to a personally owned cloud storage service, which company rules prohibit. HR and information systems first confirmed the facts, determining it was not an intentional data exfiltration but a lapse of judgment stemming from insufficient awareness of the rule and a heavy workload, and responded with additional training for the employee along with a horizontal check for similar cases elsewhere in the department. Furthermore, three employees departed during this quarter, and a checklist confirmed that in every case, the account was disabled and privileges revoked on the day of departure. Meanwhile, two employees transferred during the same period, and an inventory found one case of "privilege accumulation"--access permission to the old department's folder still remaining a month after the transfer--which was corrected immediately. Running this whole cycle continuously through the year--education -> visualization through drills -> thorough communication of rules -> root-cause analysis and recurrence prevention when a violation occurs -> thorough privilege management at onboarding/offboarding/transfer--is the practice that continuously reduces risk rooted in "people."

PhaseWhat is donePurpose
OnboardingIssue account with least privilegePrevent granting more privilege than needed
While employedRegular training + targeted-attack drillsSustain awareness, identify weak points
TransferPrivilege inventory, revoke unneeded privilegesPrevent privilege accumulation
OffboardingDisable account on day of departurePrevent post-departure unauthorized access
Warning

Trap: "an employee who falls for a targeted-attack drill should be subject to disciplinary action" is wrong--the drill's purpose is to understand the organization's weak points and improve training, and making individual punishment the main goal chills reporting and cooperation, making it harder to grasp the real situation. Also, "a departed employee's account may stay active until handover work is finished" is wrong--disabling it on the day of departure is the principle, and handover work should be completed while the employee is still on staff. Furthermore, "it is fine to leave a transferred employee's old-department privileges as they are" is wrong--privilege accumulation creates an unnecessary access path and should be revoked through periodic inventory.

Employee training, drills, policy.
Security that people uphold

5.3.4Section summary

  • The purpose of a targeted-attack drill is identifying weak points and improving training, not punishment. Sustain awareness through regularly repeated employee education
  • Issue accounts with least privilege at hiring; disable on the day of departure. Prevent privilege accumulation through inventory at transfer
  • Rules take hold not just by being posted but through read-confirmation and repeated training. On a violation, confirm the facts, then consider discipline and recurrence prevention separately; a no-blame culture encourages early sharing

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. A targeted-attack drill found that one department's link-click rate was far above the company-wide average. What is the most appropriate response to this result?

Q2. An employee is departing the company. From an information security management standpoint, by when should the account be disabled and privileges revoked?

Q3. It came to light that an employee had saved work materials to a personally owned cloud storage service, which the rules prohibit. Fact-finding determined it was not intentional misconduct but a lapse of judgment from insufficient awareness of the rule and a heavy workload. What is the most appropriate response?

Check your understandingPractice questions for Chapter 5: Practice (Exam B)

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.