CISM · Question #4
A recent audit found that an organization's new user accounts are not set up uniformly. Which of the following is MOST important for the information security manager to review?
The correct answer is D. Standards. To address non-uniform user account setup, the information security manager should review standards, as they provide mandatory requirements for consistent configuration.
Question
A recent audit found that an organization's new user accounts are not set up uniformly. Which of the following is MOST important for the information security manager to review?
Options
- ASecurity policies
- BAutomated controls
- CGuidelines
- DStandards
How the community answered
(52 responses)- A12% (6)
- B4% (2)
- C6% (3)
- D79% (41)
Why each option
To address non-uniform user account setup, the information security manager should review standards, as they provide mandatory requirements for consistent configuration.
Security policies are high-level statements of intent and objectives, providing the "what" and "why," but typically lack the specific, mandatory instructions for uniform setup.
Automated controls are implementations of policies and standards, but reviewing the controls themselves without understanding the underlying documentation might not fix the root cause of non-uniformity.
Guidelines offer recommendations and best practices, which are helpful but not mandatory and thus do not enforce uniformity as effectively as standards.
Standards specify mandatory, repeatable actions and configurations that ensure consistency, like a uniform user account setup, making them the most critical document to review when non-uniformity is discovered. Adherence to established standards ensures that all new accounts meet a defined baseline of security and configuration.
Concept tested: Security policies, standards, and guidelines
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-100.pdf
Topics
Community Discussion
No community discussion yet for this question.