Security Policies & Procedures Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Policies & Procedures flashcards as text
During a security investigation, an investigator discovers a policy violation but no criminal act. The most appropriate action is to:
Answer: Document findings and refer to HR or management per organizational procedures
Policy violations are handled through organizational disciplinary processes, typically involving HR, not unilateral investigator action.
A 'need-to-know' principle in security policy means access to information is granted based on:
Answer: Both job function requirements AND appropriate clearance level
Need-to-know requires that both a valid job requirement AND proper authorization/clearance exist before granting information access.
Which policy governs how an organization responds when a security breach is discovered?
Answer: Incident Response Policy
An Incident Response Policy defines roles, procedures, and timelines for detecting, containing, and recovering from security incidents.
Policy review cycles are important because:
Answer: Threat landscapes, regulations, and business operations change over time
Regular reviews ensure policies remain relevant as threats evolve, regulations change, and organizational processes shift.
A visitor management policy most directly supports which security principle?
Answer: Physical access control and accountability
Visitor management policies control and document who enters facilities, supporting physical access control and creating an accountability record.
In a layered security policy framework, operational procedures differ from policies in that procedures:
Answer: Describe specific step-by-step actions to implement policy intent
Procedures provide detailed, actionable steps for staff to follow, operationalizing the broader directives established in policies.
When conducting a policy gap analysis, a security investigator is trying to identify:
Answer: Areas where current policies do not adequately address known risks
A gap analysis compares existing policies against risk requirements or standards to find areas lacking sufficient coverage.