Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium

A security auditor is reviewing an organization's change management process. The auditor discovers that critical security patches are often deployed to production systems without prior testing in a staging environment, leading to system outages. This practice violates the organization's own policy for change management. Which aspect of security governance is primarily failing?

  1. ARisk Management
  2. BSecurity Architecture
  3. CCompliance Management
  4. DPolicy Enforcement
Show answer & explanation

Correct answer: D. Policy Enforcement

The organization has a policy for change management, but the practice of deploying patches without testing indicates that this policy is not being properly enforced or adhered to, leading to security and operational issues.

Why the other options are wrong

  • A. Risk Management is about identifying, assessing, and mitigating risks. While related, the immediate issue is policy violation.
  • B. Security Architecture defines the overall security design, not the adherence to operational procedures.
  • C. Compliance Management ensures adherence to external regulations, not internal policy adherence in this specific case.

Policy Enforcement

The process of ensuring that established security policies and procedures are followed and implemented correctly throughout an organization.

  • Involves monitoring, auditing, and disciplinary actions.
  • Crucial for the effectiveness of any security policy.
  • Often supported by technical controls and security awareness training.

Memory trick: Policies, Risk, Compliance, Awareness, Enforcement.

More Security Policies and Procedures questions