risk

Missing role-based and ongoing security/privacy training

Because no role-based training program or ongoing awareness refresh exists for staff handling sensitive data or privileged systems, personnel cannot execute security procedures correctly or recognize evolving attacks, so avoidable errors and successful social-engineering compromises follow.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

category
cyber_security
domain
  • Awareness & Training
  • Human Resources / Personnel Security
taxonomy
  • iso-27005-vulnerability
  • nist-privacy-risk
inherent_rating
medium

Details

risk_id
aware-role-based-training-gap
category
cyber_security
likelihood
high
impact
medium
inherent_rating
medium
treatment
mitigate
taxonomies
  • iso-27005-vulnerability
  • nist-privacy-risk

Source

No record-specific source URL is provided.

Connections