Security Policy Development & Enforcement Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Policy Development & Enforcement flashcards as text
Which policy type governs the overall information security program and is typically signed by the CEO or Board?
Answer: Program policy
A program policy (also called an organizational or master policy) establishes the overall security program, its scope, and executive commitment at the highest organizational level.
During policy development, the security team discovers that implementing a required control will cost significantly more than the risk it mitigates. What is the BEST course of action?
Answer: Document a formal risk acceptance and explore cost-effective compensating controls
When control costs exceed risk value, formal risk acceptance by appropriate leadership — combined with compensating controls — is the proper risk management response.
A newly hired employee is onboarded without completing security policy acknowledgment. Which risk does this PRIMARILY create?
Answer: Inability to enforce policy violations against the employee legally
Without a signed acknowledgment, the organization lacks documented proof that the employee was informed of policies, weakening any disciplinary or legal action for violations.
Which practice ensures that security policies address emerging threats not anticipated when the policies were originally written?
Answer: Conducting threat-intelligence-informed policy gap analysis
Threat-intelligence-informed gap analysis compares current policy coverage against emerging threat vectors to identify and address policy deficiencies proactively.
What is the MAIN purpose of separating duties within a security policy governance structure?
Answer: To ensure no single individual can both create and approve policy changes without oversight
Separation of duties in governance prevents conflicts of interest and fraud by ensuring that policy creation, review, and approval are handled by different individuals or groups.
An organization wants to ensure its security policies are consistently interpreted across multiple international offices. Which approach is MOST effective?
Answer: Create a global policy framework with region-specific supplemental standards
A global framework with regional supplements allows consistent core requirements while accommodating local legal, regulatory, and cultural differences.
Which activity BEST demonstrates that a security policy is being actively enforced rather than just documented?
Answer: Conducting regular compliance audits with documented findings and remediation tracking
Regular compliance audits with tracked findings and remediation actions provide evidence that the policy is operationally enforced and not merely theoretical.