Security Policies & Procedures Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Policies & Procedures flashcards as text
Which document typically defines the acceptable use of an organization's information systems and assets?
Answer: Acceptable Use Policy
An Acceptable Use Policy (AUP) formally defines how employees may use organizational IT resources and assets.
A 'clean desk policy' in a security context is primarily designed to:
Answer: Prevent unauthorized access to sensitive information left in plain view
Clean desk policies require employees to secure sensitive documents and lock screens when away, preventing unauthorized information access.
When a security policy conflicts with an employee's job function, the proper course of action is to:
Answer: Seek a formal policy exception or waiver through appropriate channels
Formal exception processes allow legitimate operational needs to be accommodated while maintaining documented governance oversight.
Which type of security control is a policy that requires dual authorization for high-risk transactions?
Answer: Preventive control
Dual authorization requirements are preventive controls because they stop unauthorized actions before they occur.
A 'separation of duties' policy is most effective at preventing:
Answer: Insider fraud and collusion
Separation of duties ensures no single individual can complete a fraudulent transaction alone, making insider fraud much harder to commit.
The primary purpose of a data classification policy is to:
Answer: Assign protection levels to information based on sensitivity
Data classification policies categorize information (e.g., public, internal, confidential, secret) so appropriate security controls can be applied.
Which element is essential in a written security policy to ensure enforceability?
Answer: Clear consequences for policy violations
Enforceable policies must specify consequences for violations so employees understand the stakes and management can act consistently.