Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresEasy

A small business is developing its first set of security policies. They are concerned about employees accidentally downloading malware from untrusted websites. Which type of policy would be most effective in guiding employee behavior to mitigate this specific risk?

  1. AAcceptable Use Policy (AUP)
  2. BData Classification Policy
  3. CBusiness Continuity Policy
  4. DPassword Policy
Show answer & explanation

Correct answer: A. Acceptable Use Policy (AUP)

An Acceptable Use Policy (AUP) specifically defines what employees are and are not allowed to do with company IT resources, including internet usage, which directly addresses the risk of downloading malware from untrusted sites.

Why the other options are wrong

  • B. Data classification deals with how data is categorized and handled based on sensitivity, not employee internet usage.
  • C. Business continuity plans focus on maintaining operations during disruptions, not daily employee internet use.
  • D. A password policy dictates password strength and management, unrelated to website browsing.

Acceptable Use Policy (AUP)

A document that outlines the rules and guidelines for how employees or users are permitted to use an organization's IT assets and resources.

  • Defines appropriate and inappropriate system usage.
  • Helps protect organizational assets from misuse.
  • Often includes guidelines for internet and email use.

Memory trick: Guiding behavior is about setting clear rules for action.

More Security Policies and Procedures questions