CAS-001 · Question #36
The company is considering issuing non-standard tablet computers to executive management. Which of the following is the FIRST step the security manager should perform?
The correct answer is D. Develop the use case for the devices and perform a risk analysis. The first step is to develop the use case for the devices and perform a risk analysis (D). Before any technology is deployed - especially to executives who handle sensitive data - the security manager must understand what the devices will be used for (the use case) and what…
Question
The company is considering issuing non-standard tablet computers to executive management. Which of the following is the FIRST step the security manager should perform?
Options
- AApply standard security policy settings to the devices.
- BSet up an access control system to isolate the devices from the network.
- CIntegrate the tablets into standard remote access systems.
- DDevelop the use case for the devices and perform a risk analysis.
How the community answered
(38 responses)- A5% (2)
- B11% (4)
- C3% (1)
- D82% (31)
Explanation
The first step is to develop the use case for the devices and perform a risk analysis (D). Before any technology is deployed - especially to executives who handle sensitive data - the security manager must understand what the devices will be used for (the use case) and what risks they introduce to the organization (risk analysis). This analysis determines what security controls are appropriate, whether the risk is acceptable, and how to integrate the devices safely. Applying security policy settings (A), isolating devices via access control (B), and integrating into remote access systems (C) are all actions that follow from and are informed by the risk analysis. Starting with technical implementation before understanding the risk would be putting the cart before the horse.
Topics
Community Discussion
No community discussion yet for this question.