CSI Security Policies & Procedures 2 — Questions and Answers
Question 1: Which document typically defines the acceptable use of an organization's information systems and assets?
- Incident Response Plan
- Acceptable Use Policy (Correct answer)
- Business Continuity Plan
- Risk Assessment Report
Correct answer: Acceptable Use Policy
An Acceptable Use Policy (AUP) formally defines how employees may use organizational IT resources and assets.
Question 2: A 'clean desk policy' in a security context is primarily designed to:
- Improve workplace ergonomics
- Prevent unauthorized access to sensitive information left in plain view (Correct answer)
- Reduce clutter for fire safety compliance
- Standardize office aesthetics
Correct answer: Prevent unauthorized access to sensitive information left in plain view
Clean desk policies require employees to secure sensitive documents and lock screens when away, preventing unauthorized information access.
Question 3: When a security policy conflicts with an employee's job function, the proper course of action is to:
- Ignore the policy if the job requires it
- Seek a formal policy exception or waiver through appropriate channels (Correct answer)
- Modify the policy without approval
- Resign from the conflicting duty
Correct answer: Seek a formal policy exception or waiver through appropriate channels
Formal exception processes allow legitimate operational needs to be accommodated while maintaining documented governance oversight.
Question 4: Which type of security control is a policy that requires dual authorization for high-risk transactions?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Dual authorization requirements are preventive controls because they stop unauthorized actions before they occur.
Question 5: A 'separation of duties' policy is most effective at preventing:
- Natural disasters
- Insider fraud and collusion (Correct answer)
- External cyberattacks
- Equipment theft
Correct answer: Insider fraud and collusion
Separation of duties ensures no single individual can complete a fraudulent transaction alone, making insider fraud much harder to commit.
Question 6: The primary purpose of a data classification policy is to:
- Organize files alphabetically for retrieval
- Assign protection levels to information based on sensitivity (Correct answer)
- Determine data storage hardware specifications
- Establish employee database access schedules
Correct answer: Assign protection levels to information based on sensitivity
Data classification policies categorize information (e.g., public, internal, confidential, secret) so appropriate security controls can be applied.
Question 7: Which element is essential in a written security policy to ensure enforceability?
- Technical jargon understandable only to IT staff
- Clear consequences for policy violations (Correct answer)
- Lengthy historical background on security threats
- References to competitor security practices
Correct answer: Clear consequences for policy violations
Enforceable policies must specify consequences for violations so employees understand the stakes and management can act consistently.
Which document typically defines the acceptable use of an organization's information systems and assets?