An organization wants to promote a risk-aware culture. Which of the following actions is most effective in encouraging employees to report incidents without fear?
A non-punitive reporting policy removes the fear of disciplinary consequences, which is the primary barrier to incident disclosure. By guaranteeing that honest reporters are not blamed, it directly satisfies the stem's constraint of encouraging employees to report incidents without fear, increasing early detection.
Why this answer
A non-punitive incident reporting policy is the most effective action because it directly removes the fear of retaliation or blame, which is the primary psychological barrier to reporting security incidents. By guaranteeing that employees will not face disciplinary action for reporting their own mistakes or observed issues, the organization fosters psychological safety and encourages timely disclosure. This aligns with the CRISC principle that a risk-aware culture requires trust and openness, which cannot be achieved through training or metrics alone if fear persists.
Exam trap
The trap here is that candidates often choose 'Conducting annual security awareness training' because they equate awareness with culture change, but the question specifically targets the barrier of fear, which training alone cannot remove.
How to eliminate wrong answers
Option B is wrong because annual security awareness training, while important for knowledge, does not address the emotional or cultural barrier of fear; employees may still hide incidents if they believe reporting will lead to punishment. Option C is wrong because publishing risk metrics on the intranet is a communication tactic that informs but does not create a safe reporting environment; it may even increase anxiety if metrics highlight failures without a supportive policy. Option D is wrong because providing incentives for risk identification can inadvertently encourage gaming the system or reporting only low-risk items, and it does not eliminate the fear of consequences for reporting one's own errors or serious incidents.