CAS-002 · Question #546
The IT department of a large telecommunications company has developed and finalized a set of security solutions and policies which have been approved by upper management for deployment within the…
The correct answer is C. discuss requirements with stakeholders from the various internal departments. Security policy development must begin with internal stakeholder requirements gathering before any vendor engagement or solution design can occur.
Question
The IT department of a large telecommunications company has developed and finalized a set of security solutions and policies which have been approved by upper management for deployment within the company. During the development of the security solutions and policies, the FIRST thing the IT department should have done was:
Options
- Acontact vendor management so the RFI and RFP process can be started as soon as possible.
- Bcontact an independent consultant who can tell them what policies and solutions they need.
- Cdiscuss requirements with stakeholders from the various internal departments.
- Dinvolve facilities management early in the project so they can plan for the new security
How the community answered
(51 responses)- A2% (1)
- B4% (2)
- C92% (47)
- D2% (1)
Why each option
Security policy development must begin with internal stakeholder requirements gathering before any vendor engagement or solution design can occur.
Initiating the RFI/RFP vendor process before requirements are defined leads to purchasing solutions that may not address actual business needs.
Engaging an external consultant before gathering internal requirements skips the essential context-setting step and may result in generic, non-tailored policies.
Stakeholder requirements gathering is the foundational first step in any security program development lifecycle. Without understanding the specific business needs, risk tolerance, and operational constraints of each internal department, any policies or solutions developed risk being misaligned, non-compliant with business processes, or rejected during implementation. This aligns with frameworks like NIST SP 800-100 which emphasize requirements elicitation before solution design.
Involving facilities management is appropriate but is a subset of stakeholder engagement and not the single most important first action.
Concept tested: Security policy development lifecycle stakeholder requirements
Source: https://csrc.nist.gov/publications/detail/sp/800-100/final
Topics
Community Discussion
No community discussion yet for this question.