Security Policies & Procedures Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Policies & Procedures flashcards as text
A security investigator is asked to evaluate whether a policy is 'effective.' Which metric is most relevant?
Answer: The number of incidents that the policy was designed to prevent that still occurred
Policy effectiveness is measured by whether incidents the policy was designed to prevent actually decreased, not by the document's length or distribution.
When a new government regulation requires changes to an organization's security posture, the first internal step should be to:
Answer: Review and update affected policies to ensure regulatory alignment
Regulatory changes should first trigger a policy review and update process to ensure the organization's governance framework reflects new requirements.
Which describes 'policy sprawl' and why it is a problem in large organizations?
Answer: An unmanaged proliferation of overlapping, outdated, or conflicting policies that create confusion
Policy sprawl creates governance gaps and contradictions, making it difficult for employees to identify which policy governs their situation and increasing compliance risk.
An employee claims they were unaware of a security policy they violated. The strongest organizational defense is to demonstrate:
Answer: Signed acknowledgment records showing the employee received, read, and understood the policy
Signed acknowledgment records provide documented proof that an individual was informed of and understood a specific policy, making the 'unawareness' defense untenable.
What is the primary purpose of a 'chain of custody' procedure in security investigations?
Answer: To document the handling of evidence to preserve its integrity and admissibility
Chain of custody procedures document every person who handled evidence and when, ensuring its integrity is preserved for legal or disciplinary proceedings.
A 'zero tolerance' policy in a security context means:
Answer: Specified violations result in consistent, predetermined consequences without exception based on mitigating factors
Zero tolerance policies specify that certain violations trigger defined consequences consistently, removing discretion that might allow favoritism or inconsistency.
Which factor most commonly causes security policies to fail in practice?
Answer: Lack of visible management support and consistent enforcement
When management does not visibly enforce policies or models non-compliance, employees perceive the policies as optional, leading to widespread non-adherence.