CSI Security Policies & Procedures 3 — Questions and Answers
Question 1: During a security investigation, an investigator discovers a policy violation but no criminal act. The most appropriate action is to:
- Take no action since no crime was committed
- Document findings and refer to HR or management per organizational procedures (Correct answer)
- Publicly announce the violation to deter others
- Immediately terminate the employee
Correct answer: Document findings and refer to HR or management per organizational procedures
Policy violations are handled through organizational disciplinary processes, typically involving HR, not unilateral investigator action.
Question 2: A 'need-to-know' principle in security policy means access to information is granted based on:
- Employee seniority and years of service
- Job function requirements regardless of clearance level
- Both job function requirements AND appropriate clearance level (Correct answer)
- Management preference for trusted employees
Correct answer: Both job function requirements AND appropriate clearance level
Need-to-know requires that both a valid job requirement AND proper authorization/clearance exist before granting information access.
Question 3: Which policy governs how an organization responds when a security breach is discovered?
- Acceptable Use Policy
- Incident Response Policy (Correct answer)
- Retention Policy
- Password Policy
Correct answer: Incident Response Policy
An Incident Response Policy defines roles, procedures, and timelines for detecting, containing, and recovering from security incidents.
Question 4: Policy review cycles are important because:
- Regulators require annual policy reprinting
- Threat landscapes, regulations, and business operations change over time (Correct answer)
- Employees forget policies that are not frequently reissued
- Legal departments charge fees only when policies are updated
Correct answer: Threat landscapes, regulations, and business operations change over time
Regular reviews ensure policies remain relevant as threats evolve, regulations change, and organizational processes shift.
Question 5: A visitor management policy most directly supports which security principle?
- Confidentiality of financial data
- Physical access control and accountability (Correct answer)
- Network traffic encryption
- Employee background screening
Correct answer: Physical access control and accountability
Visitor management policies control and document who enters facilities, supporting physical access control and creating an accountability record.
Question 6: In a layered security policy framework, operational procedures differ from policies in that procedures:
- Apply only to executive leadership
- Describe specific step-by-step actions to implement policy intent (Correct answer)
- Override policies when conflicts arise
- Require government approval before implementation
Correct answer: Describe specific step-by-step actions to implement policy intent
Procedures provide detailed, actionable steps for staff to follow, operationalizing the broader directives established in policies.
Question 7: When conducting a policy gap analysis, a security investigator is trying to identify:
- Financial losses from past incidents
- Areas where current policies do not adequately address known risks (Correct answer)
- Employees who have violated policies most frequently
- The cost of implementing new security technology
Correct answer: Areas where current policies do not adequately address known risks
A gap analysis compares existing policies against risk requirements or standards to find areas lacking sufficient coverage.
During a security investigation, an investigator discovers a policy violation but no criminal act.
The most appropriate action is to: