CAS-002 · Question #561
A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a strong personal…
The correct answer is B. 1) Consult legal and regulatory requirements. Security policy must be grounded in legal and regulatory requirements first to ensure an objective, compliance-driven foundation independent of vendor influence.
Question
A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a strong personal and professional relationship with the senior level staff, have a good handle on compliance and regulatory standards. Therefore, the executive level managers are allowing vendors to play a large role in writing the policy. Having experienced this type of environment in previous positions, and being aware that vendors may not always put the company's interests first, the IT Director decides that while vendor support is important, it is critical that the company writes the policy objectively. Which of the following is the recommendation the IT Director should present to senior staff?
Options
- A
- Consult legal, moral, and ethical standards;
- B
- Consult legal and regulatory requirements;
- C
- Draft General Organizational Policy;
- D
- Draft a Specific Company Policy Plan;
How the community answered
(48 responses)- A25% (12)
- B58% (28)
- C13% (6)
- D4% (2)
Why each option
Security policy must be grounded in legal and regulatory requirements first to ensure an objective, compliance-driven foundation independent of vendor influence.
Consulting moral and ethical standards introduces subjective criteria that vary by individual and organization, producing an inconsistent framework that is difficult to enforce or audit against defined compliance requirements.
Beginning with legal and regulatory requirements anchors the policy to externally mandated, verifiable standards such as HIPAA, PCI-DSS, or SOX rather than to vendor preferences shaped by business relationships. These frameworks define non-negotiable baselines that protect the organization from legal liability regardless of what any vendor recommends. Starting here gives the IT Director the objective authority needed to counter executive pressure to let vendors drive policy content.
Drafting a General Organizational Policy before identifying legal and regulatory requirements risks producing a document that omits or contradicts mandatory compliance controls.
Drafting a Specific Company Policy Plan before establishing the regulatory baseline can result in policies that are too narrow or misaligned with legally required security controls.
Concept tested: Security policy development grounded in regulatory compliance requirements
Source: https://csrc.nist.gov/publications/detail/sp/800-12/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.