nerdexam
CompTIA

CAS-002 · Question #690

Within a large organization, the corporate security policy states that personal electronic devices are not allowed to be placed on the company network. There is considerable pressure from the…

The correct answer is B. Review the security policy. When legitimate business requirements conflict with an existing security policy, the correct governance response is to formally review and revise the policy rather than making ad-hoc exceptions or blanket refusals.

Integration of Computing, Communications and Business Disciplines

Question

Within a large organization, the corporate security policy states that personal electronic devices are not allowed to be placed on the company network. There is considerable pressure from the company board to allow smartphones to connect and synchronize email and calendar items of board members and company executives. Which of the following options BEST balances the security and usability requirements of the executive management team?

Options

  • AAllow only the executive management team the ability to use personal devices on the
  • BReview the security policy.
  • CStand firm on disallowing non-company assets from connecting to the network as the assets
  • DAllow only certain devices that are known to have the ability of being centrally managed.

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    56% (14)
  • C
    24% (6)
  • D
    8% (2)

Why each option

When legitimate business requirements conflict with an existing security policy, the correct governance response is to formally review and revise the policy rather than making ad-hoc exceptions or blanket refusals.

AAllow only the executive management team the ability to use personal devices on the

Allowing only executives to use personal devices without a policy review creates an undocumented exception that is inconsistent, unauditable, and difficult to enforce or expand in a controlled manner.

BReview the security policy.Correct

Security policies are living documents that must be reviewed and updated when business needs change, especially when pressure comes from authoritative stakeholders like the board of directors. Reviewing the policy allows the organization to formally assess risk, define acceptable-use conditions for personal devices - such as requiring MDM enrollment - and document the new controls, balancing both security and usability in a governed, repeatable way.

CStand firm on disallowing non-company assets from connecting to the network as the assets

Refusing all personal devices ignores a legitimate business requirement from the board and fails to balance organizational security with operational usability needs.

DAllow only certain devices that are known to have the ability of being centrally managed.

Restricting to centrally manageable devices is a sound technical control, but implementing it without formally revising the policy leaves the organization operating outside its own documented security framework.

Concept tested: Security policy review and governance for BYOD

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-100.pdf

Topics

#BYOD#MDM#security policy#executive management

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice