212-82 · Question #163
CyberX, an acclaimed cybersecurity firm with a diverse clientele ranging from financial institutions to healthcare providers, has been approached by NexusCorp. NexusCorp, a global supply chain…
The correct answer is B. Stakeholder involvement in policy formulation. For a large, geographically dispersed organization with diverse employee tech proficiency, involving stakeholders in policy formulation is the primary consideration to ensure policies are effective, relevant, and accepted across the complex structure.
Question
CyberX, an acclaimed cybersecurity firm with a diverse clientele ranging from financial institutions to healthcare providers, has been approached by NexusCorp. NexusCorp, a global supply chain giant, seeks assistance in drafting a new security policy after a series of cyber-attacks that highlighted vulnerabilities in its existing protocols. While NexusCorp uses state-of-the-art technology, its security policies have not kept pace. It needs a policy that acknowledges its complex organizational structure, vast geographic spread, and diversity in employee tech proficiency. Which should be CyberX's primary consideration in this scenario?
Options
- ARegular update schedules for software and hardware components.
- BStakeholder involvement in policy formulation.
- CUse of the latest encryption algorithms.
- DEmphasis on stringent password policies.
How the community answered
(47 responses)- A6% (3)
- B66% (31)
- C19% (9)
- D9% (4)
Why each option
For a large, geographically dispersed organization with diverse employee tech proficiency, involving stakeholders in policy formulation is the primary consideration to ensure policies are effective, relevant, and accepted across the complex structure.
Regular update schedules for software and hardware components are crucial operational security practices but are a tactical implementation detail, not the primary strategic consideration for drafting a new policy that addresses complex organizational and human factors.
For a global supply chain giant with a complex organizational structure, vast geographic spread, and diverse employee tech proficiency, stakeholder involvement is the primary consideration in policy formulation. Engaging stakeholders from different departments and regions ensures the policies are realistic, enforceable, understood, and accepted by all affected parties, making them more effective and reducing resistance to adoption across the diverse environment.
Using the latest encryption algorithms is an important technical control for data protection, but it's a specific technical requirement within a policy, not the overarching primary consideration for formulating a policy for a diverse global organization.
Emphasis on stringent password policies is a fundamental security control, but like encryption, it's a specific policy element. The primary challenge in this scenario is creating a policy that is workable and adopted across a complex, diverse organization, which stakeholder involvement best addresses.
Concept tested: Security policy development (stakeholder involvement)
Source: https://learn.microsoft.com/en-us/security/compass/security-policy-procedures
Topics
Community Discussion
No community discussion yet for this question.