CSS Security Policy Development & Enforcement 2 — Questions and Answers
Question 1: Under the NIST Cybersecurity Framework, which function encompasses the development of organizational security policies?
- Detect
- Identify (Correct answer)
- Protect
- Respond
Correct answer: Identify
The Identify function includes governance activities such as establishing cybersecurity policies, roles, and responsibilities.
Question 2: A security policy states that all employees must complete annual security awareness training. Which policy enforcement mechanism is MOST effective for ensuring compliance?
- Sending reminder emails to all employees
- Linking training completion to annual performance reviews (Correct answer)
- Posting the policy on the intranet
- Issuing verbal warnings to non-compliant staff
Correct answer: Linking training completion to annual performance reviews
Tying training completion to performance reviews creates an organizational accountability mechanism that directly motivates compliance.
Question 3: Which document type provides step-by-step instructions for implementing a security policy requirement?
- Standard
- Guideline
- Procedure (Correct answer)
- Baseline
Correct answer: Procedure
Procedures are detailed, step-by-step instructions that tell employees exactly how to carry out policy requirements.
Question 4: An organization's acceptable use policy (AUP) is BEST described as which type of security policy?
- Issue-specific policy (Correct answer)
- System-specific policy
- Program policy
- Regulatory policy
Correct answer: Issue-specific policy
Issue-specific policies address particular topics such as acceptable use of organizational assets and systems.
Question 5: During a policy review cycle, a security manager discovers that a control in the data classification policy conflicts with a recently enacted state privacy law. What is the FIRST action to take?
- Immediately suspend the conflicting policy control
- Notify legal counsel and initiate a formal policy exception
- Update the policy to align with the law after management approval (Correct answer)
- Continue using the existing policy until the next scheduled review
Correct answer: Update the policy to align with the law after management approval
Regulatory requirements supersede internal policy, so the policy must be updated through the formal change process to achieve legal compliance.
Question 6: Which of the following BEST describes the purpose of a policy exception process?
- To allow permanent deviations from security requirements
- To document and manage temporary or justified departures from policy (Correct answer)
- To identify employees who cannot comply with policies
- To replace outdated policy requirements
Correct answer: To document and manage temporary or justified departures from policy
A policy exception process provides a controlled, documented method for managing cases where strict policy adherence is not feasible, typically including compensating controls.
Question 7: A new remote work policy requires VPN use for all corporate data access. An employee working from a hotel reports the VPN is blocked. Which is the MOST appropriate immediate response?
- Allow the employee to access data without VPN for the duration of the trip
- Advise the employee to use personal hotspot and proceed without VPN
- Have the employee defer work until VPN access is restored or provide a compliant alternative (Correct answer)
- Ask IT to create a temporary VPN bypass for the employee
Correct answer: Have the employee defer work until VPN access is restored or provide a compliant alternative
Maintaining policy integrity requires either restoring compliant access or deferring work, rather than accepting an uncontrolled risk.
Under the NIST Cybersecurity Framework, which function encompasses the development of organizational security policies?