2026 Licensing & Certification Curricula (Securities, Cloud, IT, Real Estate, Bar & CPA) are now live
Chapter 5 • Domain 55.4

5.4 Personnel Security, Social Engineering Training & Business Continuity

Enforce HR personnel controls (Separation of Duties, Mandatory Vacations), continuous phishing training, and Business Continuity Plans (BCP).

🎯 Key CompTIA Security+ Exam Takeaways

  • Separation of Duties (SoD) divides mission-critical workflows among multiple personnel to prevent fraud, sabotage, and error.
  • Mandatory Vacations require employees in sensitive roles to take consecutive time off, allowing temporary replacements to uncover fraudulent schemes.
  • Clean desk and clear screen policies prevent visual snooping (shoulder surfing) of confidential documents and displays.
  • Security awareness programs use realistic, simulated phishing campaigns paired with constructive just-in-time training to build a defensive culture.
  • Business Continuity Planning (BCP) ensures essential business operations continue functioning during and immediately following a major crisis.

Personnel security establishes internal controls governing human workflows, employee onboarding, role separation, and continuous education. Even the most sophisticated technical firewalls can be undermined if internal personnel are unmonitored or untrained.

To prevent internal fraud and collusion, enterprises enforce strict operational policies. Separation of Duties (SoD) ensures that high-risk processes (such as authorizing invoices and issuing payments) cannot be executed by a single individual. Mandatory Vacations require personnel in sensitive financial or administrative roles to take consecutive days away from their workstations, during which another employee steps in and performs their duties; this operational rotation routinely uncovers ongoing embezzlement or unauthorized activities that require constant maintenance by the perpetrator. At the physical layer, Clean Desk and Clear Screen policies require locking away sensitive paperwork and configuring short screen timeouts to defeat visual eavesdropping (shoulder surfing).

Human defense is reinforced through continuous security awareness training. Modern training programs move away from boring annual lectures in favor of regular, realistic simulated phishing campaigns. When an employee clicks on a simulated lure, best pedagogical practice provides immediate, constructive 'just-in-time' training highlighting the exact red flags present in the email, building a positive, vigilant reporting culture. Finally, Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP) define the emergency procedures, succession planning, and alternate communications needed to keep critical business operations functional during a major crisis.

⚠️ Common Pearson VUE Exam Traps

  • Treating security awareness training as a once-a-year check-the-box presentation; effective training requires continuous micro-learning and monthly phishing simulations.
  • Using public shaming or immediate termination when employees click simulated phishing links; punitive reactions create a culture of fear where employees hide real incidents.

Knowledge Checkpoint

Knowledge Checkpoint • Section 5.4

An accounts payable specialist is caught writing fraudulent company checks to a fake shell corporation and reconciling the ledger personally to hide the deficit. Which two personnel security policies work together to prevent a single employee from executing unauthorized transactions and uncover ongoing internal fraud?