Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresHard

A security engineer is tasked with creating a new procedure for handling sensitive customer data. The organization's overarching data protection policy mandates that 'all personally identifiable information (PII) must be encrypted both in transit and at rest.' Which of the following best describes the role of the security engineer in translating this policy into an effective procedure?

  1. ATo train end-users on why encryption is necessary.
  2. BTo define the strategic importance of data encryption.
  3. CTo assess the legal implications of non-compliance.
  4. DTo specify the encryption algorithms, tools, and steps for implementation.
Show answer & explanation

Correct answer: D. To specify the encryption algorithms, tools, and steps for implementation.

The policy states 'what' must be done (PII encrypted). The security engineer's role in creating a procedure is to define the 'how' – the specific technical details, algorithms, tools, and step-by-step instructions for implementing that encryption.

Why the other options are wrong

  • A. Training users on 'why' is part of awareness, not the technical procedure itself.
  • B. Defining strategic importance is a policy-level activity, not a procedural one.
  • C. Assessing legal implications falls to legal and compliance teams, not the procedure writer.

Procedure Development

The process of creating detailed, step-by-step instructions that guide individuals or systems in performing a specific task or process in a consistent and secure manner.

  • Translates high-level policies into actionable steps.
  • Ensures consistency and reduces errors.
  • Requires technical expertise for implementation details.

Memory trick: Policy is the goal, procedure is the map to get there.

More Security Policies and Procedures questions