Policies and Awareness Training

Study ISC2 CC best-practice security policies and awareness training: data handling, passwords, AUP, BYOD, change management, privacy, and social engineering.

Security policies and awareness training turn security expectations into repeatable behavior. CC questions often test whether the answer improves behavior, reduces risky actions, or defines the correct process.

Policy map

Policy What it controls
Data handling classification, storage, sharing, retention, disposal
Password creation, reuse, rotation or change triggers, MFA alignment
Acceptable Use Policy permitted use of company systems
BYOD personal-device access, security requirements, support boundaries
Change management documentation, approval, testing, rollback
Privacy personal-data handling and legal/organizational obligations

Awareness topics

Topic Exam-safe behavior
Phishing report through approved channel, do not click or forward broadly
Social engineering verify identity and follow procedure
Password protection use approved password/MFA practices and do not share credentials
AI tools do not paste sensitive data into unapproved public tools
Incident reporting report quickly, preserve evidence, and avoid unauthorized investigation

Strong-answer pattern

The best policy/training answer usually combines:

  • clear rule
  • user training
  • enforcement or monitoring
  • reporting path
  • periodic review

Awareness without policy is weak. Policy without training and evidence is also weak.

Revised on Monday, June 15, 2026