nerdexam
(ISC)2

CISSP · Question #1067

What is the FIRST step for an organization to take before allowing personnel to access social media from a corporate device or user account?

The correct answer is B. Publish an acceptable usage policy. The acceptable usage policy (AUP) is the foundation of defining how corporate resources, including devices and accounts, can be used. Before allowing employees to access social media on corporate devices, the organization must clearly outline the expectations, responsibilities…

Submitted by yaw92· Mar 5, 2026Security and Risk Management

Question

What is the FIRST step for an organization to take before allowing personnel to access social media from a corporate device or user account?

Options

  • APublish a social media guidelines document.
  • BPublish an acceptable usage policy.
  • CDocument a procedure for accessing social media sites.
  • DDeliver security awareness training.

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    94% (33)
  • D
    3% (1)

Explanation

The acceptable usage policy (AUP) is the foundation of defining how corporate resources, including devices and accounts, can be used. Before allowing employees to access social media on corporate devices, the organization must clearly outline the expectations, responsibilities, and limits for use, including: Prohibited behaviors (e.g., posting confidential information, using social media for personal gain). Security requirements (e.g., ensuring devices are secure, using strong passwords). Potential consequences for violating the policy. The AUP sets the rules and guidelines that ensure employees understand what is acceptable and what is not, providing a baseline for managing social media use in the workplace.

Topics

#Acceptable Use Policy#AUP#social media policy#security policy

Community Discussion

No community discussion yet for this question.

Full CISSP Practice