CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceMedium

A Chief Information Security Officer (CISO) is evaluating the organization's adherence to various compliance standards. They discover that while many individual controls are implemented, there is no overarching process to ensure that these controls are consistently applied and regularly reviewed across all systems and departments. Which aspect of a governance framework is most directly lacking?

  1. APolicy Enforcement Mechanisms
  2. BRisk Register Maintenance
  3. CSecurity Awareness Training
  4. DIncident Response Playbooks
Show answer & explanation

Correct answer: A. Policy Enforcement Mechanisms

The lack of an overarching process to consistently apply and regularly review controls indicates a deficiency in Policy Enforcement Mechanisms, which are essential for ensuring that security policies and controls are actively implemented and maintained throughout the organization.

Why the other options are wrong

  • B. Risk Register Maintenance tracks identified risks but doesn't directly address the consistent application of controls.
  • C. Security Awareness Training educates users but doesn't provide the mechanisms for enforcing technical or procedural controls.
  • D. Incident Response Playbooks guide actions during security incidents but don't ensure the ongoing application and review of preventative controls.

Policy Enforcement Mechanisms

The processes, tools, and procedures used to ensure that security policies and controls are consistently implemented, monitored, and maintained across an organization.

  • Ensures consistent application of controls.
  • Involves monitoring, auditing, and review.
  • Crucial for effective governance and compliance.

Memory trick: Controls without enforcement are just good intentions.

More Governance, Risk and Compliance questions