nerdexam
(ISC)2

CSSLP · Question #230

Which of the following documents is defined as a source document, which is most useful for the ISSE when classifying the needed security functionality?

The correct answer is A. Information Protection Policy (IPP). The Information Protection Policy (IPP) is a foundational document that provides the high-level directives and requirements for protecting an organization's information assets. For an Information System Security Engineer (ISSE), this policy is crucial for classifying and…

Secure Software Requirements

Question

Which of the following documents is defined as a source document, which is most useful for the ISSE when classifying the needed security functionality?

Options

  • AInformation Protection Policy (IPP)
  • BIMM
  • CSystem Security Context
  • DCONOPS

How the community answered

(42 responses)
  • A
    86% (36)
  • B
    10% (4)
  • C
    2% (1)
  • D
    2% (1)

Why each option

The Information Protection Policy (IPP) is a foundational document that provides the high-level directives and requirements for protecting an organization's information assets. For an Information System Security Engineer (ISSE), this policy is crucial for classifying and determining the specific security functionalities required for systems, ensuring alignment with organizational security goals.

AInformation Protection Policy (IPP)Correct

An Information Protection Policy (IPP) serves as a high-level strategic document that outlines an organization's overall approach, rules, and requirements for protecting its information assets. For an Information System Security Engineer (ISSE), this policy is the primary source document for understanding the organization's security posture and objectives. It is most useful for classifying the needed security functionality because it dictates the types of data that need protection, the acceptable risk levels, and the general security controls that must be implemented, thereby guiding the selection and design of specific security features.

BIMM

IMM likely refers to an "Information Management Manual" or similar, which typically details procedures for managing information, but it is not generally the primary source for defining security functionality classification.

CSystem Security Context

System Security Context describes the environment in which a system operates and its security requirements, but it often derives its directives from higher-level policies like the IPP, making the IPP more foundational for classification.

DCONOPS

CONOPS (Concept of Operations) describes how an organization intends to operate a system or achieve its mission, focusing on operational aspects rather than the overarching security requirements and classifications.

Concept tested: Information Security - Policy documents

Topics

#Security Policy#Security Requirements#Source Documents#Information Protection

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice