Assignment 3: Designing a Social Engineering Awareness Program for a Large
Corporation
Imagine you are an Information Security consultant for a large corporation with a global
presence. The corporation has recognized the increasing threat of social engineering attacks and
is committed to raising awareness among its employees. Write a three to five-page paper in
which you:
1. Social Engineering Threat Landscape: Provide an overview of the current social
engineering threat landscape. Identify common tactics such as phishing, pretexting, and
baiting. Explain how these tactics can exploit human vulnerabilities within an
organization.
2. Developing an Awareness Program: Design a comprehensive social engineering
awareness program for the corporation. Include strategies for educating employees about
the different types of social engineering attacks and how to recognize and report
suspicious activities.
3. Simulated Phishing Exercises: Propose the implementation of simulated phishing
exercises as part of the awareness program. Explain how these exercises can help
employees recognize phishing attempts and reinforce good security practices.
4. Employee Engagement: Discuss strategies to ensure active engagement and participation
in the awareness program. Consider the use of interactive training modules, workshops,
and ongoing communication channels to keep employees informed and vigilant.
Your assignment must follow the provided formatting requirements, be typed, double-spaced,
using Times New Roman font (size 12), with one-inch margins on all sides. Citations and
references must follow APA or school-specific format.
Include a cover page containing the title of the assignment, the student’s name, the professor’s
name, the course title, and the date. The cover page and the reference page are not included in
the required assignment page length.
The specific course learning outcomes associated with this assignment are:
●Describe the role of information systems security (ISS) compliance and its relationship to
U.S. compliance laws.
●Use technology and information resources to research issues in security strategy and
policy formation.
●Write clearly and concisely about topics related to information technology audit and
control using proper writing mechanics and technical style conventions.
Click4here4to view the grading rubric.
Grading for this assignment will be based on answer quality, logic / organization of the paper,
and language and writing skills, using the following rubric.
Points: 50 Assignment 3: Designing a Social Engineering Awareness Program for a Large Corporat
Criteria Unacceptable
Below 60% F
Meets Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exempla
90-100%
1. Analyze
proper
physical
access control
safeguards
and provide
Did not submit or
incompletely
analyzed proper
physical access
control safeguards
and did not submit or
Insufficiently
analyzed proper
physical access
control
safeguards and
insufficiently
Partially4analy
zed proper
physical
access control
safeguards
and
Satisfactorily
analyzed proper
physical access
control
safeguards and
satisfactorily
Thoroughly
analyzed pro
physical acc
control
safeguards a
thoroughly
sound
recommendati
ons to be
employed in
the registrar's
office.
Weight: 21%
incompletely
provided sound
recommendations to
be employed in the
registrar's office.
provided sound
recommendations
to be employed
in the registrar's
office.
partially4provi
ded sound
recommendati
ons to be
employed in
the registrar's
office.
provided sound
recommendations
to be employed in
the registrar's
office.
provided sou
recommenda
s to be
employed in
registrar's of
2.
Recommend
the proper
audit controls
to be
employed in
the registrar's