CSL Security Policy Development & Compliance 3 — Questions and Answers
Question 1: A new regulation requires organizations to appoint a Data Protection Officer (DPO). Which policy document should be updated FIRST to reflect this governance change?
- Incident response plan
- Information security charter or governance policy (Correct answer)
- Vulnerability management policy
- Network access control policy
Correct answer: Information security charter or governance policy
The information security charter or governance policy defines organizational roles and accountability structures, making it the appropriate document to reflect a new mandated role.
Question 2: During a compliance audit, an auditor asks for evidence that the password policy is being enforced technically. Which artifact BEST demonstrates technical enforcement?
- A signed copy of the password policy
- Active Directory group policy settings screenshot (Correct answer)
- Employee security awareness training records
- The IT manager's attestation letter
Correct answer: Active Directory group policy settings screenshot
Active Directory or directory service configuration screenshots show that password requirements are technically enforced rather than relying solely on user compliance.
Question 3: An organization's security policy states that all laptops must use full-disk encryption. An executive requests an exemption because encryption slows their device. What should the security team do FIRST?
- Grant the exemption because executives have elevated authority
- Deny the exemption with no further action
- Initiate a formal risk acceptance process documenting the risk and requiring executive sign-off (Correct answer)
- Escalate to the board without informing the executive
Correct answer: Initiate a formal risk acceptance process documenting the risk and requiring executive sign-off
A formal risk acceptance process ensures the exception is documented, the residual risk is acknowledged, and accountability is assigned to the individual requesting the exemption.
Question 4: Which compliance framework uses a tiered approach where Tier 1 represents partial implementation and Tier 4 represents adaptive cybersecurity practices?
- ISO 27001
- NIST Cybersecurity Framework (CSF) (Correct answer)
- COBIT 5
- CIS Controls
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST CSF defines four implementation tiers (Partial, Risk-Informed, Repeatable, Adaptive) to help organizations assess the maturity of their cybersecurity risk management practices.
Question 5: A security policy requires that all media containing sensitive data be sanitized before disposal. Which NIST publication provides the primary guidance on media sanitization techniques?
- NIST SP 800-53
- NIST SP 800-88 (Correct answer)
- NIST SP 800-61
- NIST SP 800-37
Correct answer: NIST SP 800-88
NIST SP 800-88, Guidelines for Media Sanitization, defines clearing, purging, and destroying methods appropriate for different media types and data sensitivity levels.
Question 6: Which policy type sits at the TOP of the organizational security policy hierarchy?
- Procedure
- Standard
- Guideline
- Master information security policy (Correct answer)
Correct answer: Master information security policy
The master or enterprise information security policy is the highest-level document that establishes the organization's security intent and is supported by standards, guidelines, and procedures below it.
Question 7: When a security policy conflicts with a legal requirement, what is the CORRECT action?
- Follow the security policy because it was established first
- Follow the legal requirement and initiate a policy update process (Correct answer)
- Consult only the security team to resolve the conflict
- Suspend the conflicting policy until the next annual review
Correct answer: Follow the legal requirement and initiate a policy update process
Legal obligations supersede internal policy; the organization must comply with the law while updating internal policy through the proper governance process to eliminate the conflict.
A new regulation requires organizations to appoint a Data Protection Officer (DPO).
Which policy document should be updated FIRST to reflect this governance change?