Comprehensive and Detailed Explanation From Exact Extract:
ISO/IEC 27035 and ISO/IEC 27001 emphasize that information security awareness and training must extend to all personnel, not just those in technical roles. Clause 7.3.2 of ISO/IEC 27035-2 specifically states that “training should be made available to all staff,” including non-technical users, third-party service providers, contractors, and any personnel with access to organizational assets or systems.
The rationale is that every user is a potential entry point for cyber threats. Whether through phishing, social engineering, or misconfiguration, untrained staff can unintentionally compromise the organization’s security posture. Therefore, organizations must ensure that everyone—especially new hires, contractors, and third-party partners—is trained on incident reporting procedures, security responsibilities, and escalation paths.
Reference Extracts:
ISO/IEC 27035-2:2016, Clause 7.3.2: “Training and awareness activities should be targeted at all users of the organization's systems and services.”
ISO/IEC 27001:2022, Control 6.3: “Ensure that personnel are aware of their information security responsibilities.”
Correct answer: C
—