Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium
A security team is implementing a new patch management procedure. The procedure dictates that all critical security patches must be applied to production servers within 72 hours of release, followed by a mandatory system reboot. Which characteristic of an effective security procedure is best demonstrated by this example?
- AIt is broadly applicable to all systems.
- BIt focuses on strategic security objectives.
- CIt primarily addresses legal compliance requirements.
- DIt is specific, measurable, and actionable.
Show answer & explanationAnswer & explanation
Correct answer: D. It is specific, measurable, and actionable.
The procedure specifies 'all critical security patches,' 'within 72 hours,' and 'mandatory system reboot,' making it specific, measurable, and actionable, which are key characteristics of an effective security procedure.
Why the other options are wrong
- A. While important, 'broad applicability' isn't the most prominent characteristic demonstrated by the detailed steps.
- B. Procedures implement strategic objectives, but the example highlights the tactical, detailed nature.
- C. While it might contribute to compliance, the example focuses on the operational details, not the compliance aspect itself.
Effective Security Procedure
A detailed, step-by-step instruction set designed to ensure consistent and correct execution of security tasks, directly supporting security policies.
- Must be clear, concise, and easy to follow.
- Should be specific, measurable, and actionable.
- Helps achieve compliance and reduce human error.
Memory trick: Effective procedures are like clear recipes: precise and easy to follow.