Your Corporate Information Security Policy should include which of the following?

Posted by: Pdfprep Category: 712-50 Tags: , ,

Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation.

Your Corporate Information Security Policy should include which of the following?
A . Roles and responsibilities
B . Information security theory
C . Incident response contacts
D . Desktop configuration standards

Answer: A

Leave a Reply

Your email address will not be published.