SY0-301 · Question #136
Pete, a security analyst, has been informed that the development team has plans to develop an application which does not meet the company's password policy. Which of the following should Pete do NEXT?
The correct answer is B. Tell the application development manager to code the application to adhere to the company's password policy. When a development team plans to violate an existing security policy, the security analyst's immediate responsibility is to direct them to comply with that policy through the appropriate manager. Escalation or policy changes are premature before attempting direct enforcement.
Question
Pete, a security analyst, has been informed that the development team has plans to develop an application which does not meet the company's password policy. Which of the following should Pete do NEXT?
Options
- AContact the Chief Information Officer and ask them to change the company password policy so that
- BTell the application development manager to code the application to adhere to the company's password policy.
- CAsk the application development manager to submit a risk acceptance memo so that the issue can be
- DInform the Chief Information Officer of non-adherence to the security policy so that the developers can
How the community answered
(40 responses)- A3% (1)
- B85% (34)
- C10% (4)
- D3% (1)
Why each option
When a development team plans to violate an existing security policy, the security analyst's immediate responsibility is to direct them to comply with that policy through the appropriate manager. Escalation or policy changes are premature before attempting direct enforcement.
Changing the company password policy to accommodate non-compliant development undermines the purpose of the policy and is not the security analyst's role or the appropriate first response.
The security analyst's primary duty is to enforce existing security policy, and the correct next step is to inform the application development manager directly so the application is coded to meet the company's password policy requirements. This is the most direct and appropriate response before considering escalation or policy exceptions.
Requesting a risk acceptance memo is appropriate only after exhausting enforcement options - asking for a formal exception before directing the team to comply skips the enforcement step.
Escalating immediately to the CIO bypasses the direct communication channel with the development manager, which should be the first corrective action taken by the analyst.
Concept tested: Security policy enforcement and analyst responsibilities
Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-security-policy
Topics
Community Discussion
No community discussion yet for this question.