โ† All CSS Flashcard Decks

Security Policy Development & Enforcement Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Policy Development & Enforcement flashcards as text
  1. Under the NIST Cybersecurity Framework, which function encompasses the development of organizational security policies?

    Answer: Identify

    The Identify function includes governance activities such as establishing cybersecurity policies, roles, and responsibilities.

  2. A security policy states that all employees must complete annual security awareness training. Which policy enforcement mechanism is MOST effective for ensuring compliance?

    Answer: Linking training completion to annual performance reviews

    Tying training completion to performance reviews creates an organizational accountability mechanism that directly motivates compliance.

  3. Which document type provides step-by-step instructions for implementing a security policy requirement?

    Answer: Procedure

    Procedures are detailed, step-by-step instructions that tell employees exactly how to carry out policy requirements.

  4. An organization's acceptable use policy (AUP) is BEST described as which type of security policy?

    Answer: Issue-specific policy

    Issue-specific policies address particular topics such as acceptable use of organizational assets and systems.

  5. During a policy review cycle, a security manager discovers that a control in the data classification policy conflicts with a recently enacted state privacy law. What is the FIRST action to take?

    Answer: Update the policy to align with the law after management approval

    Regulatory requirements supersede internal policy, so the policy must be updated through the formal change process to achieve legal compliance.

  6. Which of the following BEST describes the purpose of a policy exception process?

    Answer: To document and manage temporary or justified departures from policy

    A policy exception process provides a controlled, documented method for managing cases where strict policy adherence is not feasible, typically including compensating controls.

  7. A new remote work policy requires VPN use for all corporate data access. An employee working from a hotel reports the VPN is blocked. Which is the MOST appropriate immediate response?

    Answer: Have the employee defer work until VPN access is restored or provide a compliant alternative

    Maintaining policy integrity requires either restoring compliant access or deferring work, rather than accepting an uncontrolled risk.