CAS-001 · Question #78
A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a strong personal…
The correct answer is B. 1) Consult legal and regulatory requirements. Security policy development should be grounded first in legal and regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS, local laws) because these are external, objective obligations that apply to the company regardless of vendor relationships. Starting with legal and regulatory…
Question
A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a strong personal and professional relationship with the senior level staff, have a good handle on compliance and regulatory standards. Therefore, the executive level managers are allowing vendors to play a large role in writing the policy. Having experienced this type of environment in previous positions, and being aware that vendors may not always put the company's interests first, the IT Director decides that while vendor support is important, it is critical that the company writes the policy objectively. Which of the following is the recommendation the IT Director should present to senior staff?
Options
- A
- Consult legal, moral, and ethical standards;
- B
- Consult legal and regulatory requirements;
- C
- Draft General Organizational Policy;
- D
- Draft a Specific Company Policy Plan;
How the community answered
(44 responses)- A7% (3)
- B77% (34)
- C11% (5)
- D5% (2)
Explanation
Security policy development should be grounded first in legal and regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS, local laws) because these are external, objective obligations that apply to the company regardless of vendor relationships. Starting with legal and regulatory requirements ensures the policy is compliant, defensible, and company-interest-first rather than vendor-interest-first. Consulting legal requirements before drafting policy prevents vendors from steering the company toward solutions that serve the vendor's commercial interests but may not meet compliance obligations. General organizational or specific company policy drafting comes later in the process, after the legal foundation is established.
Topics
Community Discussion
No community discussion yet for this question.