108 ◾ Information Security Fundamentals
Desired Outcomes
Security awareness programs are aimed at producing behavioral change or rein-
forcement. To measure the program’s effectiveness, we need to know what the
desired change was and to what extent it was completed and internalized. erefore,
among the first questions to be addressed when implementing a program are “What
specific behavioral changes are objectives of the security awareness program at this
organization? How do we want people to change? How do we know that they’ve
changed?” ese are not always easy to answer, but there are some change category
indicators that can help tell us if the program’s desired effects are taking place.
Change category indicators for training
More frequent pa ...