Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresEasy

An organization is developing a new security policy. The policy states that all employees must use strong, unique passwords for all company systems and that multi-factor authentication (MFA) is mandatory for remote access. This policy is then communicated to all employees through email and a mandatory training session. Which characteristic of a well-defined security policy is best exemplified by the mandatory training session?

  1. AFlexible
  2. BComprehensive
  3. CCommunicated
  4. DEnforceable
Show answer & explanation

Correct answer: C. Communicated

The mandatory training session serves as a direct method to ensure the policy is effectively communicated to all employees, which is a key characteristic of a sound security policy.

Why the other options are wrong

  • A. Flexibility relates to adaptability, not the initial promulgation of the policy.
  • B. Comprehensiveness refers to the scope of coverage, not the dissemination method.
  • D. Enforceability relates to the ability to compel compliance, not the act of informing.

Communicated Security Policy

A characteristic of a security policy where its contents are effectively disseminated and understood by all relevant stakeholders within an organization.

  • Ensures awareness and understanding among employees.
  • Can involve training, email, intranet, or other communication channels.
  • Crucial for policy effectiveness and compliance.

Memory trick: CLEAR policies are best: Communicated, Legible, Enforceable, Adaptable, Relevant.

More Security Policies and Procedures questions