CGEIT · Question #129
An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should
The correct answer is B. Obtain senior management input based on identified risk.. When a zero-tolerance security policy causes significant business disruption, the first governance step is to obtain senior management input, informed by identified risks and impacts, to collectively re-evaluate and adjust the policy.
Question
An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?
Options
- ADirect the development of an em il usage policy.
- BObtain senior management input based on identified risk.
- CRecommend business sign-off on the zero-tolerance policy.
- DIntroduce an exception process.
How the community answered
(20 responses)- A5% (1)
- B70% (14)
- C10% (2)
- D15% (3)
Why each option
When a zero-tolerance security policy causes significant business disruption, the first governance step is to obtain senior management input, informed by identified risks and impacts, to collectively re-evaluate and adjust the policy.
Directing the development of an email usage policy is a tactical action that comes after senior management has provided guidance on how to balance security and usability.
A zero-tolerance policy, especially one causing significant business disruption, indicates a potential imbalance between security and operational efficiency. The initial governance step involves presenting the identified risks (disruption, productivity loss) to senior management to gain their perspective and secure their collective decision on whether to modify the policy or accept the business impact. This ensures that any policy adjustment is aligned with the enterprise's overall risk appetite and strategic objectives.
Recommending business sign-off on the existing zero-tolerance policy doesn't address the current disruption; it merely reinforces the problematic policy without seeking resolution.
Introducing an exception process is a potential solution, but it's a tactical implementation detail that should only be considered after senior management has acknowledged the issue and approved a strategic direction for addressing the policy's impact.
Concept tested: IT governance for security policy balancing
Source: https://www.isaca.org/resources/cobit/cobit-2019-framework-introduction-and-methodology/chapter-3/enabling-principles-for-governance-and-management
Topics
Community Discussion
No community discussion yet for this question.