EC-Council
712-50 · Question #251
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and…
The correct answer is B. Roles and responsibilities. See the full explanation below for the reasoning.
Question
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation. Your Corporate Information Security Policy should include which of the following?
Options
- AInformation security theory
- BRoles and responsibilities
- CIncident response contacts
- DDesktop configuration standards
How the community answered
(26 responses)- A4% (1)
- B77% (20)
- C12% (3)
- D8% (2)
Community Discussion
No community discussion yet for this question.