โ† All CSI Flashcard Decks

Security Policies & Procedures Flashcards

7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Policies & Procedures flashcards as text
  1. Which document typically defines the acceptable use of an organization's information systems and assets?

    Answer: Acceptable Use Policy

    An Acceptable Use Policy (AUP) formally defines how employees may use organizational IT resources and assets.

  2. A 'clean desk policy' in a security context is primarily designed to:

    Answer: Prevent unauthorized access to sensitive information left in plain view

    Clean desk policies require employees to secure sensitive documents and lock screens when away, preventing unauthorized information access.

  3. When a security policy conflicts with an employee's job function, the proper course of action is to:

    Answer: Seek a formal policy exception or waiver through appropriate channels

    Formal exception processes allow legitimate operational needs to be accommodated while maintaining documented governance oversight.

  4. Which type of security control is a policy that requires dual authorization for high-risk transactions?

    Answer: Preventive control

    Dual authorization requirements are preventive controls because they stop unauthorized actions before they occur.

  5. A 'separation of duties' policy is most effective at preventing:

    Answer: Insider fraud and collusion

    Separation of duties ensures no single individual can complete a fraudulent transaction alone, making insider fraud much harder to commit.

  6. The primary purpose of a data classification policy is to:

    Answer: Assign protection levels to information based on sensitivity

    Data classification policies categorize information (e.g., public, internal, confidential, secret) so appropriate security controls can be applied.

  7. Which element is essential in a written security policy to ensure enforceability?

    Answer: Clear consequences for policy violations

    Enforceable policies must specify consequences for violations so employees understand the stakes and management can act consistently.