CAS-002 · Question #172
A security consultant is called into a small advertising business to recommend which security policies and procedures would be most helpful to the business. The business is comprised of 20…
The correct answer is A. Password Policy B. Data Classification Policy. For a small 20-person business with employee and client data but no remote server access, a Password Policy and Data Classification Policy are the most foundational and broadly applicable controls to implement first.
Question
A security consultant is called into a small advertising business to recommend which security policies and procedures would be most helpful to the business. The business is comprised of 20 employees, operating off of two shared servers. One server houses employee data and the other houses client data. All machines are on the same local network. Often these employees must work remotely from client sites, but do not access either of the servers remotely. Assuming no security policies or procedures are in place right now, which of the following would be the MOST applicable for implementation? (Select TWO).
Options
- APassword Policy
- BData Classification Policy
- CWireless Access Procedure
- DVPN Policy
- EDatabase Administrative Procedure
How the community answered
(45 responses)- A78% (35)
- C4% (2)
- D11% (5)
- E7% (3)
Why each option
For a small 20-person business with employee and client data but no remote server access, a Password Policy and Data Classification Policy are the most foundational and broadly applicable controls to implement first.
A Password Policy is the most universally applicable security control for any organization, protecting access to both shared servers and individual workstations with minimal complexity and immediate effect.
A Data Classification Policy is critical here because the company maintains two distinct categories of sensitive data - employee data and client data on separate servers - and classification helps prioritize appropriate protections for each category.
A Wireless Access Procedure is not applicable because the scenario makes no mention of wireless infrastructure in this small office environment.
A VPN Policy is unnecessary because the scenario explicitly states that employees do not access either server remotely when working from client sites.
A Database Administrative Procedure is too operationally complex and granular for a 20-person company and is not among the most critical foundational policies needed.
Concept tested: Foundational security policy prioritization for small businesses
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-12r1.pdf
Topics
Community Discussion
No community discussion yet for this question.