nerdexam
CompTIA

CAS-002 · Question #561

A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a strong personal…

The correct answer is B. 1) Consult legal and regulatory requirements. Security policy must be grounded in legal and regulatory requirements first to ensure an objective, compliance-driven foundation independent of vendor influence.

Integration of Computing, Communications and Business Disciplines

Question

A mid-level company is rewriting its security policies and has halted the rewriting progress because the company's executives believe that its major vendors, who have cultivated a strong personal and professional relationship with the senior level staff, have a good handle on compliance and regulatory standards. Therefore, the executive level managers are allowing vendors to play a large role in writing the policy. Having experienced this type of environment in previous positions, and being aware that vendors may not always put the company's interests first, the IT Director decides that while vendor support is important, it is critical that the company writes the policy objectively. Which of the following is the recommendation the IT Director should present to senior staff?

Options

  • A
    1. Consult legal, moral, and ethical standards;
  • B
    1. Consult legal and regulatory requirements;
  • C
    1. Draft General Organizational Policy;
  • D
    1. Draft a Specific Company Policy Plan;

How the community answered

(48 responses)
  • A
    25% (12)
  • B
    58% (28)
  • C
    13% (6)
  • D
    4% (2)

Why each option

Security policy must be grounded in legal and regulatory requirements first to ensure an objective, compliance-driven foundation independent of vendor influence.

A1) Consult legal, moral, and ethical standards;

Consulting moral and ethical standards introduces subjective criteria that vary by individual and organization, producing an inconsistent framework that is difficult to enforce or audit against defined compliance requirements.

B1) Consult legal and regulatory requirements;Correct

Beginning with legal and regulatory requirements anchors the policy to externally mandated, verifiable standards such as HIPAA, PCI-DSS, or SOX rather than to vendor preferences shaped by business relationships. These frameworks define non-negotiable baselines that protect the organization from legal liability regardless of what any vendor recommends. Starting here gives the IT Director the objective authority needed to counter executive pressure to let vendors drive policy content.

C1) Draft General Organizational Policy;

Drafting a General Organizational Policy before identifying legal and regulatory requirements risks producing a document that omits or contradicts mandatory compliance controls.

D1) Draft a Specific Company Policy Plan;

Drafting a Specific Company Policy Plan before establishing the regulatory baseline can result in policies that are too narrow or misaligned with legally required security controls.

Concept tested: Security policy development grounded in regulatory compliance requirements

Source: https://csrc.nist.gov/publications/detail/sp/800-12/rev-1/final

Topics

#security policy development#regulatory compliance#vendor management#policy framework

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice