nerdexam
(ISC)2

CISSP · Question #152

Refer to the information below to answer the question. A large organization uses unique identifiers and requires them at the start of every system session. Application access is based on job classific

The correct answer is B. Security standards. The best place to specify the permitted access for each department and job classification combination is the security standards. Security standards are the documents that define the specific and measurable requirements or rules for the implementation and maintenance of the securi

Submitted by thandi_sa· Mar 5, 2026Security and Risk Management

Question

Refer to the information below to answer the question. A large organization uses unique identifiers and requires them at the start of every system session. Application access is based on job classification. The organization is subject to periodic independent reviews of access controls and violations. The organization uses wired and wireless networks and remote access. The organization also uses secure connections to branch offices and secure backup and recovery strategies for selected information and processes. Following best practice, where should the permitted access for each department and job classification combination be specified?

Options

  • ASecurity procedures
  • BSecurity standards
  • CHuman resource policy
  • DHuman resource standards

How the community answered

(22 responses)
  • B
    86% (19)
  • C
    5% (1)
  • D
    9% (2)

Explanation

The best place to specify the permitted access for each department and job classification combination is the security standards. Security standards are the documents that define the specific and measurable requirements or rules for the implementation and maintenance of the security policies and procedures. Security standards can help to ensure the consistency and the compliance of the security controls and measures across the organization, and to support the security objectives and principles, such as the least privilege and the separation of duties. Specifying the permitted access for each department and job classification combination in the security standards can help to enforce the role-based access control (RBAC) methodology, which assigns the permissions and privileges to the users or the devices based on their roles or functions in the organization. Security procedures, human resource policy, and human resource standards are not the best places to specify the permitted access for each department and job classification combination, as they are related to the steps or actions for the execution or operation of the security controls or measures, the general and strategic guidelines or objectives for the management or administration of the human resources, or the specific and measurable requirements or rules for the implementation and maintenance of the human resource policy, not the role-based access control methodology.

Topics

#security standards#access control documentation#security policies#information security governance

Community Discussion

No community discussion yet for this question.

Full CISSP Practice