Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium

An organization's security policy states that all critical servers must be patched within 48 hours of a patch release for high-severity vulnerabilities. However, the system administrators have developed a detailed, step-by-step document outlining the specific process for patch deployment, including testing procedures, rollback plans, and communication protocols. This detailed document serves what primary purpose within the organization's security framework?

  1. ASecurity guideline
  2. BSecurity standard
  3. CSecurity policy
  4. DSecurity procedure
Show answer & explanation

Correct answer: D. Security procedure

A detailed, step-by-step document outlining how to perform a specific task, such as patch deployment, is the definition of a security procedure.

Why the other options are wrong

  • A. A security guideline offers recommendations, not mandatory, detailed steps.
  • B. A security standard specifies mandatory requirements for hardware/software configuration, not step-by-step processes.
  • C. A security policy is a high-level statement of intent, not detailed steps.

Security Procedure

A detailed, step-by-step instruction set for performing specific security-related tasks or actions.

  • Explains 'how' to implement policies and standards.
  • Highly specific and often role-based.
  • Ensures consistency and repeatability of security operations.

Memory trick: Policies are high, Procedures are low, Standards are in between, Guidelines just flow.

More Security Policies and Procedures questions