Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium
An organization's security policy states that all critical servers must be patched within 48 hours of a patch release for high-severity vulnerabilities. However, the system administrators have developed a detailed, step-by-step document outlining the specific process for patch deployment, including testing procedures, rollback plans, and communication protocols. This detailed document serves what primary purpose within the organization's security framework?
- ASecurity guideline
- BSecurity standard
- CSecurity policy
- DSecurity procedure
Show answer & explanationAnswer & explanation
Correct answer: D. Security procedure
A detailed, step-by-step document outlining how to perform a specific task, such as patch deployment, is the definition of a security procedure.
Why the other options are wrong
- A. A security guideline offers recommendations, not mandatory, detailed steps.
- B. A security standard specifies mandatory requirements for hardware/software configuration, not step-by-step processes.
- C. A security policy is a high-level statement of intent, not detailed steps.
Security Procedure
A detailed, step-by-step instruction set for performing specific security-related tasks or actions.
- Explains 'how' to implement policies and standards.
- Highly specific and often role-based.
- Ensures consistency and repeatability of security operations.
Memory trick: Policies are high, Procedures are low, Standards are in between, Guidelines just flow.