nerdexam
CompTIA

CAS-003 · Question #278

The Chief Information Security Officer (CISO) regularly receives reports of a single department repeatedly violating the corporate security policy. The head of the department in question informs the…

The correct answer is D. Draft an MOU for the department head and CISO to approve, documenting the limits of the. D (Draft an MOU) is correct because a Memorandum of Understanding (MOU) is the appropriate formal document to acknowledge a recognized exception or special operating arrangement between two internal parties. It documents that the department's activities deviate from policy, the…

Risk Management

Question

The Chief Information Security Officer (CISO) regularly receives reports of a single department repeatedly violating the corporate security policy. The head of the department in question informs the CISO that the offending behaviors are a result of necessary business activities. The CISO assigns a junior security administrator to solve the issue. Which of the following is the BEST course of action for the junior security administrator to take?

Options

  • AWork with the department head to find an acceptable way to change the business needs so
  • BDraft an RFP for the purchase of a COTS product or consulting services to solve the
  • CWork with the CISO and department head to create an SLA specifying the response times
  • DDraft an MOU for the department head and CISO to approve, documenting the limits of the

How the community answered

(53 responses)
  • A
    15% (8)
  • B
    6% (3)
  • C
    4% (2)
  • D
    75% (40)

Explanation

D (Draft an MOU) is correct because a Memorandum of Understanding (MOU) is the appropriate formal document to acknowledge a recognized exception or special operating arrangement between two internal parties. It documents that the department's activities deviate from policy, the business justification for doing so, and the agreed-upon security boundaries - creating accountability without requiring a policy change or external procurement. A junior admin should not unilaterally change business processes (A), spend budget on COTS products (B), or establish an SLA (C), which governs service response times, not policy exceptions. The MOU gives both the CISO and department head a documented, approved agreement rather than an ongoing undocumented violation.

Topics

#security policy#MOU#governance#compliance

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice