nerdexam
CompTIA

CAS-001 · Question #262

The IT department of a large telecommunications company has developed and finalized a set of security solutions and policies which have been approved by upper management for deployment within the…

The correct answer is C. discuss requirements with stakeholders from the various internal departments. Security solutions and policies must be grounded in actual business requirements. The very first step in any security program development is to gather requirements by discussing needs with stakeholders from all relevant internal departments (HR, Finance, Legal, Operations…

Integration of Computing, Communications and Business Disciplines

Question

The IT department of a large telecommunications company has developed and finalized a set of security solutions and policies which have been approved by upper management for deployment within the company. During the development of the security solutions and policies, the FIRST thing the IT department should have done was:

Options

  • Acontact vendor management so the RFI and RFP process can be started as soon as possible.
  • Bcontact an independent consultant who can tell them what policies and solutions they need.
  • Cdiscuss requirements with stakeholders from the various internal departments.
  • Dinvolve facilities management early in the project so they can plan for the new security hardware

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    9% (4)
  • C
    84% (36)
  • D
    5% (2)

Explanation

Security solutions and policies must be grounded in actual business requirements. The very first step in any security program development is to gather requirements by discussing needs with stakeholders from all relevant internal departments (HR, Finance, Legal, Operations, etc.). Without understanding what the business actually needs to protect and how it operates, any security policy or solution risks being misaligned with reality. Contacting vendors (A) or consultants (B) before understanding internal requirements leads to solutions that may not fit. Involving facilities (D) is appropriate later, when hardware deployment is being planned - not at the requirements-gathering stage.

Topics

#security policy#stakeholder management#requirements gathering#governance

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice