CAS-002 · Question #758
The technology steering committee is struggling with increased requirements stemming from an increase in telecommuting. The organization has not addressed telecommuting in the past. The…
The correct answer is C. Publish a policy that addresses the security requirements for working remotely with company. When an organization introduces a new operational capability like telecommuting, senior management must first publish a governing policy before any technical controls or procedures can be meaningfully defined.
Question
The technology steering committee is struggling with increased requirements stemming from an increase in telecommuting. The organization has not addressed telecommuting in the past. The implementation of a new SSL-VPN and a VOIP phone solution enables personnel to work from remote locations with corporate assets. Which of the following steps must the committee take FIRST to outline senior management's directives?
Options
- ADevelop an information classification scheme that will properly secure data on corporate systems.
- BImplement database views and constrained interfaces so remote users will be unable to access
- CPublish a policy that addresses the security requirements for working remotely with company
- DWork with mid-level managers to identify and document the proper procedures for telecommuting.
How the community answered
(24 responses)- A4% (1)
- C92% (22)
- D4% (1)
Why each option
When an organization introduces a new operational capability like telecommuting, senior management must first publish a governing policy before any technical controls or procedures can be meaningfully defined.
Developing an information classification scheme is a technical and operational task that should be informed by the policy's directives, not created before the policy exists.
Implementing database views and constrained interfaces is a technical control that can only be properly designed and scoped after policy defines what level of access remote users are authorized to have.
Policy is the foundational document that establishes senior management's directives, intent, and high-level security requirements - it must exist before any technical implementations or operational procedures can be properly scoped. All subsequent work, such as access controls, classification schemes, and user procedures, must derive from and align with this governing policy.
Documenting procedures with mid-level managers is a procedural step that operationalizes policy requirements - procedures cannot be correctly developed until the governing policy establishes the rules they must enforce.
Concept tested: Security policy as prerequisite to telecommuting controls
Source: https://csrc.nist.gov/publications/detail/sp/800-46/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.