CSL Security Policy Development & Compliance 2 — Questions and Answers
Question 1: A CISO discovers that a third-party vendor has access to sensitive data but is not covered by the organization's security policy. What is the BEST immediate step?
- Terminate the vendor contract immediately
- Issue a temporary security exception while drafting a vendor policy addendum (Correct answer)
- Apply the existing internal policy verbatim to the vendor
- Notify regulators about the policy gap before taking any action
Correct answer: Issue a temporary security exception while drafting a vendor policy addendum
A temporary exception with formal documentation preserves operations while the appropriate policy framework is developed for third-party relationships.
Question 2: Which policy governance approach requires that all security policy exceptions be approved by the CISO and documented with a defined expiration date?
- Policy waiver management (Correct answer)
- Risk acceptance framework
- Compensating control documentation
- Policy lifecycle management
Correct answer: Policy waiver management
Policy waiver management formalizes the exception process by requiring senior approval and time-bounding each deviation from standard policy.
Question 3: An organization subject to PCI DSS needs to demonstrate that its security policy is reviewed regularly. What is the minimum required review frequency per PCI DSS?
- Every 6 months
- Annually (Correct answer)
- Every 2 years
- After every security incident
Correct answer: Annually
PCI DSS Requirement 12.1 mandates that the information security policy be reviewed at least once per year and updated when the environment changes.
Question 4: When drafting an Acceptable Use Policy (AUP), which element is MOST critical to include to ensure enforceability?
- A list of all approved software applications
- A clear statement of consequences for violations (Correct answer)
- The technical specifications of monitoring tools
- A glossary of cybersecurity terminology
Correct answer: A clear statement of consequences for violations
Without defined consequences, an AUP lacks the deterrent and enforcement mechanism needed for legal and disciplinary action.
Question 5: A security leader wants to align the organization's policy framework with NIST SP 800-53. Which control family directly governs policy and procedure documentation?
- Access Control (AC)
- Planning (PL)
- Program Management (PM) (Correct answer)
- System and Services Acquisition (SA)
Correct answer: Program Management (PM)
The Program Management (PM) control family in NIST SP 800-53 addresses organization-wide information security program planning, including policy development and documentation.
Question 6: Which of the following BEST describes the difference between a security standard and a security guideline?
- Standards are optional best practices; guidelines are mandatory requirements
- Standards are mandatory requirements; guidelines are recommended but not required (Correct answer)
- Standards apply only to technical controls; guidelines apply to administrative controls
- Standards are set by regulators; guidelines are set internally
Correct answer: Standards are mandatory requirements; guidelines are recommended but not required
In a policy hierarchy, standards carry mandatory compliance requirements while guidelines offer recommended approaches that provide flexibility.
Question 7: An organization is implementing a policy to comply with HIPAA. Which policy would MOST directly address the requirement to limit access to protected health information (PHI)?
- Business continuity policy
- Minimum necessary access policy (Correct answer)
- Data retention policy
- Incident response policy
Correct answer: Minimum necessary access policy
HIPAA's Minimum Necessary standard requires covered entities to limit PHI access to only what is needed to accomplish the intended purpose, making a minimum necessary access policy directly applicable.
A CISO discovers that a third-party vendor has access to sensitive data but is not covered by the organization's security policy.
What is the BEST immediate step?