CISSP · Question #206
Regarding asset security and appropriate retention, which of the following INITIAL top three areas are important to focus on?
The correct answer is A. Security control baselines, access controls, employee awareness and training. Asset security and appropriate retention requires foundational controls centered on baselines, access management, and human awareness to protect organizational assets effectively.
Question
Regarding asset security and appropriate retention, which of the following INITIAL top three areas are important to focus on?
Options
- ASecurity control baselines, access controls, employee awareness and training
- BHuman resources, asset management, production management
- CSupply chain lead-time, inventory control, and encryption
- DPolygraphs, crime statistics, forensics
How the community answered
(23 responses)- A78% (18)
- B13% (3)
- C4% (1)
- D4% (1)
Why each option
Asset security and appropriate retention requires foundational controls centered on baselines, access management, and human awareness to protect organizational assets effectively.
Security control baselines establish the minimum required protections for asset classification and retention policies, ensuring consistent safeguarding across the organization. Access controls restrict who can interact with sensitive assets, directly supporting confidentiality and integrity during the asset lifecycle. Employee awareness and training ensure that personnel understand retention schedules, handling requirements, and disposal procedures, which are critical human-factor components in asset security.
While human resources and asset management have supporting roles, 'production management' is an operational function, not a primary domain focus in asset security and retention within information security frameworks like CISSP.
Supply chain lead-time and inventory control are logistics/operations concepts, and while encryption is a valid security control, these three together do not represent the foundational initial focus areas for asset security and retention policy.
Polygraphs, crime statistics, and forensics relate to investigative and law enforcement activities, not to the proactive governance of asset security and appropriate data retention practices.
Concept tested: Asset security retention controls and foundational security domains
Source: https://www.isc2.org/certifications/cissp/cissp-cbk
Topics
Community Discussion
No community discussion yet for this question.