CAP · Question #65
A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in…
The correct answer is B. What is being secured? C. Where is the vulnerability, threat, or risk? D. Who is expected to comply with the policy? A well-designed security policy must address: What is being secured (B) - the assets and resources under protection; Where the vulnerability, threat, or risk exists (C) - the operational or environmental context of the risk; and Who is expected to comply with the policy (D)…
Question
A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in a well designed policy? Each correct answer represents a part of the solution. Choose all that apply.
Options
- AWho is expected to exploit the vulnerability?
- BWhat is being secured?
- CWhere is the vulnerability, threat, or risk?
- DWho is expected to comply with the policy?
How the community answered
(62 responses)- A10% (6)
- B90% (56)
Explanation
A well-designed security policy must address: What is being secured (B) - the assets and resources under protection; Where the vulnerability, threat, or risk exists (C) - the operational or environmental context of the risk; and Who is expected to comply with the policy (D) - the scope of personnel and systems bound by the policy. Option A - 'Who is expected to exploit the vulnerability' - is NOT a policy requirement. Identifying potential attackers or threat actors belongs to threat modeling and risk assessment processes, not to a general security policy statement. Policies define rules and responsibilities, not attacker profiles.
Topics
Community Discussion
No community discussion yet for this question.