nerdexam
EC-Council

712-50 · Question #20

When would it be more desirable to develop a set of decentralized security policies and procedures within an enterprise environment?

The correct answer is B. When the enterprise is made up of many business units with diverse business activities, risks. Decentralized security policies are best suited when an enterprise consists of multiple business units with varied operations, risk profiles, and regulatory requirements - each unit needs tailored policies that reflect its unique threat landscape and compliance obligations…

Governance (Policy, Legal & Compliance)

Question

When would it be more desirable to develop a set of decentralized security policies and procedures within an enterprise environment?

Options

  • AWhen there is a need to develop a more unified incident response capability.
  • BWhen the enterprise is made up of many business units with diverse business activities, risks
  • CWhen there is a variety of technologies deployed in the infrastructure.
  • DWhen it results in an overall lower cost of operating the security program.

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    69% (18)
  • C
    4% (1)
  • D
    19% (5)

Explanation

Decentralized security policies are best suited when an enterprise consists of multiple business units with varied operations, risk profiles, and regulatory requirements - each unit needs tailored policies that reflect its unique threat landscape and compliance obligations rather than a one-size-fits-all approach. Option A is wrong because unified incident response is actually an argument for centralization, not decentralization - you want coordinated response across the enterprise. Option C is wrong because technology diversity is a reason to consider centralized security architecture standards, not decentralized ones. Option D is wrong because decentralization typically increases cost due to duplicated efforts, tools, and personnel across business units.

Memory tip: Think "diverse businesses = diverse policies." Decentralize when the business is diverse; centralize when the function (like incident response) needs coordination.

Topics

#decentralized governance#organizational structure#security policies#enterprise risk management

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice