ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium

A multinational corporation is developing a new cloud-based application that will process personal data of users in various jurisdictions. The legal team is reviewing the General Data Protection Regulation (GDPR) for European users, the California Consumer Privacy Act (CCPA) for California residents, and other relevant privacy laws. They are also considering internal corporate policies that mandate a higher standard of data protection than some local laws. Which aspect of security governance principles is most critical in aligning these diverse requirements into a cohesive framework?

  1. ADeveloping and enforcing security policies, standards, and procedures
  2. BEstablishing a security awareness program
  3. CImplementing a continuous monitoring system for system performance
  4. DDefining roles and responsibilities for incident response
Show answer & explanation

Correct answer: A. Developing and enforcing security policies, standards, and procedures

Developing and enforcing comprehensive security policies, standards, and procedures is crucial for harmonizing diverse legal, regulatory, and internal requirements. These documents translate high-level governance objectives into actionable rules and guidelines for the organization, ensuring consistent application across different jurisdictions and compliance with the most stringent applicable requirements.

Why the other options are wrong

  • B. Security awareness is important but doesn't directly create the cohesive framework for legal alignment.
  • C. Continuous monitoring is a technical control for performance and security, but not the governance mechanism for legal alignment.
  • D. Incident response roles are part of operational security, not the foundational governance for diverse legal requirements.

Security Policies, Standards, and Procedures

Hierarchical documentation that defines an organization's security posture, requirements, and implementation steps.

  • Policies are high-level statements of intent.
  • Standards define mandatory requirements for systems and processes.
  • Procedures provide detailed, step-by-step instructions for tasks.

Memory trick: Policies set the path, standards define the goal, procedures show the way.

More Security and Risk Management questions