GSEC · Question #141
Which of the following are examples of Issue-Specific policies all organizations should address?
The correct answer is D. Backup requirements, employee monitoring, physical access and acceptable use. Issue-specific policies address concrete, security-relevant organizational concerns such as backup procedures, acceptable use, employee monitoring, and physical access controls.
Question
Which of the following are examples of Issue-Specific policies all organizations should address?
Options
- APerimeter filtering guides, break times for employees, desktop neatness and backup procedures.
- BRogue wireless access points, auditing, break time for employees and organizational structure.
- CAudit logs, physical access, mission statements and network protocols used.
- DBackup requirements, employee monitoring, physical access and acceptable use.
How the community answered
(23 responses)- A4% (1)
- B4% (1)
- C13% (3)
- D78% (18)
Why each option
Issue-specific policies address concrete, security-relevant organizational concerns such as backup procedures, acceptable use, employee monitoring, and physical access controls.
Break times for employees and desktop neatness are administrative or HR concerns unrelated to security issue-specific policies, disqualifying this option.
Organizational structure is an administrative management concern, not a security issue-specific policy topic, making this choice incorrect.
Mission statements are high-level organizational documents, not security policies, so this choice incorrectly mixes non-security administrative content with security topics.
Backup requirements, employee monitoring, physical access controls, and acceptable use policies are all recognized issue-specific (functional) security policies that directly govern how resources, systems, and access are managed within an organization. Each topic represents a distinct security concern requiring a dedicated policy to define rules, expectations, and enforcement procedures. These are the canonical examples of issue-specific policies because they address specific behaviors and operational security practices.
Concept tested: Issue-specific security policy categories and examples
Source: https://csrc.nist.gov/publications/detail/sp/800-12/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.