nerdexam
CompTIA

CAS-001 · Question #321

The Chief Information Security Officer (CISO) regularly receives reports of a single department repeatedly violating the corporate security policy. The head of the department in question informs the…

The correct answer is D. Draft an MOU for the department head and CISO to approve, documenting the limits of the necessary. A Memorandum of Understanding (MOU) is the correct tool here. Since the department claims the policy violations are required for legitimate business activities, the junior administrator cannot simply force compliance or change business processes unilaterally. An MOU formally…

Integration of Computing, Communications and Business Disciplines

Question

The Chief Information Security Officer (CISO) regularly receives reports of a single department repeatedly violating the corporate security policy. The head of the department in question informs the CISO that the offending behaviors are a result of necessary business activities. The CISO assigns a junior security administrator to solve the issue. Which of the following is the BEST course of action for the junior security administrator to take?

Options

  • AWork with the department head to find an acceptable way to change the business needs so the
  • BDraft an RFP for the purchase of a COTS product or consulting services to solve the problem through
  • CWork with the CISO and department head to create an SLA specifying the response times of the IT
  • DDraft an MOU for the department head and CISO to approve, documenting the limits of the necessary

How the community answered

(33 responses)
  • A
    15% (5)
  • B
    9% (3)
  • C
    3% (1)
  • D
    73% (24)

Explanation

A Memorandum of Understanding (MOU) is the correct tool here. Since the department claims the policy violations are required for legitimate business activities, the junior administrator cannot simply force compliance or change business processes unilaterally. An MOU formally documents the agreed-upon exception - specifying exactly what deviations are permitted, under what conditions, and to what extent. Both the department head and CISO sign it, creating an accountable, auditable record. This balances security governance with business reality. Option A oversteps the junior admin's authority by trying to change business processes. Option B (RFP) is a procurement decision beyond a junior admin's scope. Option C (SLA) governs IT response times, not policy exceptions - it solves the wrong problem.

Topics

#MOU#security policy#governance#risk acceptance

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice