nerdexam
EC-Council

312-50V11 · Question #53

Security Policy is a definition of what it means to be secure for a system, organization or other entity. For Information Technologies, there are sub-policies like Computer Security Policy…

The correct answer is C. Confidentiality, Integrity, Availability. The CIA triad - Confidentiality, Integrity, and Availability - is the foundational framework that all IT security sub-policies are built to protect.

Information Security and Ethical Hacking Fundamentals

Question

Security Policy is a definition of what it means to be secure for a system, organization or other entity. For Information Technologies, there are sub-policies like Computer Security Policy, Information Protection Policy, Information Security Policy, network Security Policy, Physical Security Policy, Remote Access Policy, and User Account Policy. What is the main theme of the sub-policies for Information Technologies?

Options

  • AAvailability, Non-repudiation, Confidentiality
  • BAuthenticity, Integrity, Non-repudiation
  • CConfidentiality, Integrity, Availability
  • DAuthenticity, Confidentiality, Integrity

How the community answered

(20 responses)
  • B
    5% (1)
  • C
    90% (18)
  • D
    5% (1)

Why each option

The CIA triad - Confidentiality, Integrity, and Availability - is the foundational framework that all IT security sub-policies are built to protect.

AAvailability, Non-repudiation, Confidentiality

Non-repudiation is a valid security property but is not part of the CIA triad; replacing Integrity with Non-repudiation makes this set incorrect as the 'main theme' of IT security sub-policies.

BAuthenticity, Integrity, Non-repudiation

Authenticity and Non-repudiation are security concepts but neither belongs to the core CIA triad, making this combination incorrect as the foundational framework.

CConfidentiality, Integrity, AvailabilityCorrect

Confidentiality, Integrity, and Availability form the CIA triad, the universally recognized core model of information security. Every IT security sub-policy (Network Security, Remote Access, User Account, etc.) is designed to enforce or protect one or more of these three properties. NIST and other standards bodies define this triad as the central theme of all information security practice.

DAuthenticity, Confidentiality, Integrity

Authenticity is not a component of the CIA triad; Availability is the missing element here, and without it this set does not represent the correct foundational model.

Concept tested: CIA triad as foundation of IT security policies

Source: https://csrc.nist.gov/publications/detail/sp/800-12/rev-1/final

Topics

#CIA triad#security policy#confidentiality integrity availability#information security

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice