nerdexam
EC-Council

212-82 · Question #163

CyberX, an acclaimed cybersecurity firm with a diverse clientele ranging from financial institutions to healthcare providers, has been approached by NexusCorp. NexusCorp, a global supply chain…

The correct answer is B. Stakeholder involvement in policy formulation. For a large, geographically dispersed organization with diverse employee tech proficiency, involving stakeholders in policy formulation is the primary consideration to ensure policies are effective, relevant, and accepted across the complex structure.

Submitted by helene.fr· Mar 6, 2026Compliance & Legal Considerations for Cloud

Question

CyberX, an acclaimed cybersecurity firm with a diverse clientele ranging from financial institutions to healthcare providers, has been approached by NexusCorp. NexusCorp, a global supply chain giant, seeks assistance in drafting a new security policy after a series of cyber-attacks that highlighted vulnerabilities in its existing protocols. While NexusCorp uses state-of-the-art technology, its security policies have not kept pace. It needs a policy that acknowledges its complex organizational structure, vast geographic spread, and diversity in employee tech proficiency. Which should be CyberX's primary consideration in this scenario?

Options

  • ARegular update schedules for software and hardware components.
  • BStakeholder involvement in policy formulation.
  • CUse of the latest encryption algorithms.
  • DEmphasis on stringent password policies.

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    66% (31)
  • C
    19% (9)
  • D
    9% (4)

Why each option

For a large, geographically dispersed organization with diverse employee tech proficiency, involving stakeholders in policy formulation is the primary consideration to ensure policies are effective, relevant, and accepted across the complex structure.

ARegular update schedules for software and hardware components.

Regular update schedules for software and hardware components are crucial operational security practices but are a tactical implementation detail, not the primary strategic consideration for drafting a new policy that addresses complex organizational and human factors.

BStakeholder involvement in policy formulation.Correct

For a global supply chain giant with a complex organizational structure, vast geographic spread, and diverse employee tech proficiency, stakeholder involvement is the primary consideration in policy formulation. Engaging stakeholders from different departments and regions ensures the policies are realistic, enforceable, understood, and accepted by all affected parties, making them more effective and reducing resistance to adoption across the diverse environment.

CUse of the latest encryption algorithms.

Using the latest encryption algorithms is an important technical control for data protection, but it's a specific technical requirement within a policy, not the overarching primary consideration for formulating a policy for a diverse global organization.

DEmphasis on stringent password policies.

Emphasis on stringent password policies is a fundamental security control, but like encryption, it's a specific policy element. The primary challenge in this scenario is creating a policy that is workable and adopted across a complex, diverse organization, which stakeholder involvement best addresses.

Concept tested: Security policy development (stakeholder involvement)

Source: https://learn.microsoft.com/en-us/security/compass/security-policy-procedures

Topics

#Security policy#Governance#Stakeholder management#Risk management

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice