PCCET · Question #17
Which activities do local organization security policies cover for a SaaS application?
The correct answer is B. how the application can be used. The correct answer is B - how the application can be used. Local organizational security policies (such as acceptable use policies, data classification policies, and access control policies) govern the behavior of the organization's own users and staff. For a SaaS application…
Question
Which activities do local organization security policies cover for a SaaS application?
Options
- Ahow the data is backed up in one or more locations
- Bhow the application can be used
- Chow the application processes the data
- Dhow the application can transit the Internet
How the community answered
(24 responses)- B88% (21)
- C8% (2)
- D4% (1)
Explanation
The correct answer is B - how the application can be used. Local organizational security policies (such as acceptable use policies, data classification policies, and access control policies) govern the behavior of the organization's own users and staff. For a SaaS application, the organization can define and enforce policies around how employees are permitted to use the application - for example, which features are allowed, what categories of data can be stored in it, and who is authorized to access it. The organization does not control how the provider backs up data (A), how the application internally processes data (C), or how application traffic is routed across the Internet (D) - those responsibilities belong to the SaaS provider and are governed by the service contract or SLA, not local organizational policy.
Topics
Community Discussion
No community discussion yet for this question.