712-50 Question 266
Single answerUnderstanding and protecting against Social Engineering in the age of Social MediaA global company is preparing to announce a major acquisition. The CISO learns that several executives frequently post travel updates, conference attendance, and organizational announcements on public social media accounts. During previous high-profile events, the company experienced spear-phishing emails that referenced real executive travel and internal project names gathered from public sources. The CEO asks for a security response that reduces the likelihood and impact of social-engineering attacks tied to social media exposure without undermining legitimate business communications. Which action should the CISO prioritize FIRST?
- A
Temporarily prohibit all employees from using social media until the acquisition is publicly announced
- B
Implement a risk-based social media governance program that limits disclosure of sensitive business context, requires executive awareness training, and adds enhanced verification controls for high-risk requests during the announcement period
- C
Deploy a new email filtering gateway and rely on technical controls to block any phishing emails referencing the acquisition
- D
Require the public relations team to approve every employee social media post before publication
Show answer and explanation
Correct answer: B
Explanation
The strongest CCISO-aligned response is a balanced, risk-based program that combines governance, people, and process controls. In this scenario, attackers are using publicly available social media details to craft convincing spear-phishing and pretexting campaigns. Therefore, the CISO should first reduce unnecessary disclosure of sensitive contextual information, especially by high-visibility personnel, while implementing stronger verification requirements for high-risk requests during the acquisition period.
This approach reflects common best practices from security awareness, fraud prevention, and executive risk management programs. Relevant guidance includes NIST SP 800-61 for incident readiness concepts, NIST SP 800-50 for security awareness and training, and NIST SP 800-53 controls such as AT-2 (Awareness Training) and AC/PL-related governance practices. Social engineering defenses are most effective when layered: clear communication policies, executive-specific training, transaction verification, phishing-resistant authentication where possible, and technical monitoring. A mature CISO should avoid overly broad bans or dependence on a single technology and instead implement proportionate, business-aligned controls that remain effective beyond a single event.
- A. Incorrect.
This is not the best first action. A blanket prohibition is difficult to enforce, disruptive to business, and unlikely to address the underlying problem of social-engineering risk. CCISO-level decisions should balance security, business operations, and governance. A total ban may also drive communications outside approved channels and does not establish durable controls for future events.
- B. Correct.
This is the best answer. The scenario calls for reducing both likelihood and impact of social engineering derived from social media while preserving legitimate business communications. A risk-based governance approach addresses the root cause: oversharing of contextual information that enables pretexting and spear phishing. Executive-focused awareness is critical because attackers often target or impersonate senior leaders. Enhanced verification controls, such as out-of-band confirmation for payment requests, account changes, or urgent sensitive actions, directly mitigate business email compromise and pretexting during high-risk periods.
- C. Incorrect.
This is a plausible but incomplete response. Email security technology is important, but the scenario specifically highlights attacker use of public social media information to improve credibility. Technical filtering alone does not address oversharing, impersonation, vishing, SMS phishing, or fraudulent requests that bypass email defenses. At the executive level, the CISO should implement layered controls, not rely on a single technical measure.
- D. Incorrect.
This is overly restrictive and operationally inefficient. Requiring approval of every post is rarely scalable in a global enterprise and is not a proportionate first step. It also focuses on process bottlenecks rather than building a sustainable governance model based on data classification, role-based guidance, awareness, and compensating controls for high-risk transactions.