Cisco CCNP Security Core (SCOR) 350-701Security ConceptsEasy
A financial institution is implementing a new customer data platform. To comply with various industry regulations and data protection laws, they need to establish a set of rules and practices that dictate how information security is managed throughout the organization. Which component of security governance best describes this requirement?
- ASecurity policies
- BSecurity metrics
- CSecurity audits
- DRisk assessments
Show answer & explanationAnswer & explanation
Correct answer: A. Security policies
Security policies are formal documents that define the rules and practices for managing information security within an organization, directly aligning with the need to dictate how security is managed.
Why the other options are wrong
- B. Security metrics are used to measure the effectiveness of security controls, not to dictate rules.
- C. Security audits are independent examinations of security controls, not the rules themselves.
- D. Risk assessments identify and evaluate potential threats and vulnerabilities, rather than defining ongoing management rules.
Security Policies
Formal, high-level statements issued by management that dictate an organization's rules and practices for information security, guiding behavior and decision-making.
- Provide a framework for security controls and procedures.
- Ensure compliance with laws, regulations, and industry standards.
- Communicate management's expectations for security behavior.
Memory trick: Governance means Policy, Risk, Metrics, and Audits to stay secure.