← All CSS Flashcard Decks

Security Policy Development & Enforcement Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Policy Development & Enforcement flashcards as text
  1. What is the PRIMARY distinction between a security policy and a security standard?

    Answer: Policies state what must be achieved; standards specify how to achieve it

    Policies define high-level requirements and goals, while standards prescribe specific, measurable technical or operational requirements to meet those goals.

  2. Which stakeholder group is MOST critical to include during the initial development of an enterprise information security policy?

    Answer: Senior leadership and legal counsel

    Senior leadership provides authority and strategic alignment, while legal counsel ensures regulatory compliance — both are essential at the policy creation stage.

  3. A company implements a clean desk policy. Which type of security threat does this PRIMARILY mitigate?

    Answer: Insider threat via unauthorized physical access to sensitive information

    Clean desk policies reduce the risk that unauthorized individuals — including visitors or employees — view or take sensitive physical documents left unattended.

  4. Which metric BEST measures the effectiveness of a security policy enforcement program?

    Answer: Rate of policy violations detected, investigated, and resolved

    Tracking the full lifecycle of violations — detection, investigation, and resolution — demonstrates that enforcement mechanisms are actually functioning.

  5. During a merger, two organizations with conflicting data retention policies must operate together. What is the BEST approach?

    Answer: Apply the stricter of the two retention policies enterprise-wide as an interim measure

    Applying the stricter policy enterprise-wide minimizes legal and compliance risk while a unified policy is formally developed and approved.

  6. Which concept describes the practice of ensuring that security policies align with and support the organization's overall business objectives?

    Answer: Security governance

    Security governance ensures that security policies, processes, and resources are aligned with business strategy and organizational objectives.

  7. An organization's password policy mandates a minimum 12-character length. A system cannot enforce this requirement due to a technical limitation. What control type should be applied?

    Answer: Compensating control

    A compensating control is used when the primary required control cannot be implemented, providing an alternative means of meeting the security objective.