EC-Council
512-50 · Question #286
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and…
The correct answer is B. Roles and responsibilities. See the full explanation below for the reasoning.
Question
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation. Your Corporate Information Security Policy should include which of the following?
Options
- AInformation security theory
- BRoles and responsibilities
- CIncident response contacts
- DDesktop configuration standards
How the community answered
(37 responses)- A5% (2)
- B84% (31)
- C3% (1)
- D8% (3)
Community Discussion
No community discussion yet for this question.