Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium
During a routine audit, it is discovered that an organization's security policy on remote access states that 'all remote connections must be secured.' However, there is no documented procedure detailing how to establish a VPN connection, which VPN client to use, or how to troubleshoot common connection issues. This scenario highlights a gap between which two crucial elements of a security program?
- ASecurity audits and security training
- BSecurity policies and security assessments
- CSecurity awareness and incident response
- DSecurity policies and security procedures
Show answer & explanationAnswer & explanation
Correct answer: D. Security policies and security procedures
A security policy sets the high-level 'what' (e.g., 'all remote connections must be secured'), while a security procedure details the 'how' (e.g., step-by-step instructions for VPN). The absence of the latter, despite the former, indicates a gap between policies and procedures.
Why the other options are wrong
- A. Audits check compliance, and training educates, but neither directly addresses the missing procedural detail.
- B. Assessments evaluate policies, but the issue is the lack of underlying 'how-to' guidance.
- C. Awareness and incident response are distinct from the policy/procedure relationship.
Policy vs. Procedure
A security policy is a high-level statement of intent and rules (the 'what'), while a security procedure is a detailed, step-by-step guide on how to implement those rules (the 'how').
- Policies are strategic, procedures are tactical.
- Procedures ensure consistent implementation of policies.
- Both are essential for a comprehensive security program.
Memory trick: The blueprint (policy) needs clear instructions (procedure) to build.