ある会社の物理的なセキュリティ チームは、従業員がバッジを表示していないという報告を受けています。また、チームは、管理された入口で従業員がテールゲートしているのを観察しています。セキュリティ チームが今後のセキュリティ トレーニングで最も重点を置く可能性のあるトピックは次のどれですか。
正解:B
Situational awareness refers to being mindful of security risks in one's environment and taking proactive measures to mitigate them. In this scenario, employees are failing to display their identification badges and allowing unauthorized personnel to follow them into restricted areas (tailgating). These behaviors pose significant security risks, such as unauthorized access to sensitive locations.
Security training focused on situational awareness will educate employees on the importance of remaining vigilant about security practices, recognizing potential threats, and enforcing access control measures.
Social engineering involves manipulating individuals to gain unauthorized access, but this scenario highlights poor adherence to security protocols rather than deception.
Phishing is an email-based attack aimed at stealing sensitive information, which is unrelated to physical security lapses.
Acceptable use policy governs the proper use of company resources but does not specifically address tailgating or badge display issues.
Thus, situational awareness is the most relevant security training topic for addressing these concerns.