nerdexam
CompTIA

CAS-002 · Question #278

The Chief Information Security Officer (CISO) regularly receives reports of a single department repeatedly violating the corporate security policy. The head of the department in question informs the…

The correct answer is D. Draft an MOU for the department head and CISO to approve, documenting the limits of the. When a department must deviate from security policy for legitimate business reasons, a Memorandum of Understanding formally documents the agreed-upon exception and limits the liability of both parties.

Integration of Computing, Communications and Business Disciplines

Question

The Chief Information Security Officer (CISO) regularly receives reports of a single department repeatedly violating the corporate security policy. The head of the department in question informs the CISO that the offending behaviors are a result of necessary business activities. The CISO assigns a junior security administrator to solve the issue. Which of the following is the BEST course of action for the junior security administrator to take?

Options

  • AWork with the department head to find an acceptable way to change the business needs so
  • BDraft an RFP for the purchase of a COTS product or consulting services to solve the
  • CWork with the CISO and department head to create an SLA specifying the response times
  • DDraft an MOU for the department head and CISO to approve, documenting the limits of the

How the community answered

(53 responses)
  • A
    15% (8)
  • B
    4% (2)
  • C
    8% (4)
  • D
    74% (39)

Why each option

When a department must deviate from security policy for legitimate business reasons, a Memorandum of Understanding formally documents the agreed-upon exception and limits the liability of both parties.

AWork with the department head to find an acceptable way to change the business needs so

Requiring business operations to conform to security policy inverts the correct relationship - security exists to enable the business, and forcing operational changes to eliminate valid business activities exceeds the authority and scope of a junior security administrator.

BDraft an RFP for the purchase of a COTS product or consulting services to solve the

Issuing an RFP for a commercial product or consulting services is premature before the nature of the acceptable exception has been formally agreed upon, and does not resolve the documentation and governance gap that is the core problem.

CWork with the CISO and department head to create an SLA specifying the response times

A Service Level Agreement defines measurable performance targets and response times for IT services - it is the wrong instrument for formalizing a policy exception, as it does not document risk acceptance or define the limits of permitted deviation.

DDraft an MOU for the department head and CISO to approve, documenting the limits of theCorrect

An MOU between the department head and CISO formally acknowledges the policy deviation, defines its boundaries, and records accepted risk - this transforms an uncontrolled violation into a sanctioned, documented exception with accountability on both sides, which is the appropriate governance mechanism for ongoing business-driven policy conflicts.

Concept tested: Security policy exception documentation using MOU

Source: https://csrc.nist.gov/glossary/term/memorandum_of_understanding

Topics

#security policy#MOU#governance#business alignment

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice