← All CSS Flashcard Decks

Security Policy Development & Enforcement Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Policy Development & Enforcement flashcards as text
  1. Which element is MOST important to include in a security policy to ensure legal enforceability against employees?

    Answer: An acknowledgment signature or consent confirmation

    Employee acknowledgment creates a documented agreement that the individual has read, understood, and agreed to comply with the policy, which is essential for legal enforcement.

  2. A security policy requires encryption of all mobile devices. An executive refuses to apply encryption to their personal phone used for work email. How should this be handled?

    Answer: Apply a BYOD policy that requires encryption or prohibits work email on unencrypted devices

    A formal BYOD policy that mandates encryption as a condition of access applies consistently regardless of seniority and preserves policy integrity.

  3. What is the recommended frequency for reviewing and updating enterprise security policies according to best practice?

    Answer: Annually or whenever significant changes occur to the environment or regulations

    Annual review cycles — combined with trigger-based reviews for regulatory changes, incidents, or major organizational shifts — keep policies current and effective.

  4. Which approach to policy enforcement uses automated tools to prevent policy violations before they occur?

    Answer: Preventive enforcement

    Preventive enforcement uses technical controls such as DLP, firewalls, and access controls to block non-compliant actions before they happen.

  5. A healthcare organization's security policy must comply with HIPAA. This is an example of which type of policy driver?

    Answer: Regulatory/compliance driver

    HIPAA is a federal regulation that mandates specific security requirements, making regulatory compliance the primary policy driver for covered entities.

  6. Which policy framework component defines the minimum security configuration requirements for a specific technology platform?

    Answer: Baseline

    A baseline defines the minimum acceptable security configuration for a specific type of system or platform, derived from broader standards.

  7. An employee shares confidential customer data via personal email in violation of the data handling policy. Which consequence framework BEST supports consistent enforcement?

    Answer: A pre-defined disciplinary matrix tied to violation severity

    A disciplinary matrix provides consistent, documented, and graduated consequences based on violation type and severity, ensuring fair and defensible enforcement.