Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresEasy
An organization is developing a new security policy. The policy states that all employees must use strong, unique passwords for all company systems and that multi-factor authentication (MFA) is mandatory for remote access. This policy is then communicated to all employees through email and a mandatory training session. Which characteristic of a well-defined security policy is best exemplified by the mandatory training session?
- AFlexible
- BComprehensive
- CCommunicated
- DEnforceable
Show answer & explanationAnswer & explanation
Correct answer: C. Communicated
The mandatory training session serves as a direct method to ensure the policy is effectively communicated to all employees, which is a key characteristic of a sound security policy.
Why the other options are wrong
- A. Flexibility relates to adaptability, not the initial promulgation of the policy.
- B. Comprehensiveness refers to the scope of coverage, not the dissemination method.
- D. Enforceability relates to the ability to compel compliance, not the act of informing.
Communicated Security Policy
A characteristic of a security policy where its contents are effectively disseminated and understood by all relevant stakeholders within an organization.
- Ensures awareness and understanding among employees.
- Can involve training, email, intranet, or other communication channels.
- Crucial for policy effectiveness and compliance.
Memory trick: CLEAR policies are best: Communicated, Legible, Enforceable, Adaptable, Relevant.