Question 1 of 30
Examination of the data shows a significant increase in phishing attempts targeting your organization\'s employees, leading to several minor security incidents. The IT security team has proposed a new, highly restrictive policy requiring multi-factor authentication (MFA) for all internal applications, mandatory daily security awareness training modules, and a complete ban on using personal cloud storage for any work-related documents. The Chief Information Security Officer (CISO) is concerned that this policy, while technically robust, may significantly hinder employee productivity and lead to widespread resistance. What is the most professionally sound approach to developing and implementing a revised security policy in response to these incidents?
Conduct a comprehensive risk assessment to identify critical assets and specific threats, then develop policy recommendations collaboratively with input from IT operations, legal, and end-user representatives, focusing on practical, risk-based controls and clear communication.
Immediately implement the proposed policy as drafted by the IT security team, emphasizing the severity of the recent incidents and the need for immediate, stringent measures to protect the organization.
Prioritize user convenience and operational flow by implementing only basic security measures, such as password complexity rules, and deferring more complex controls like MFA to a future, less urgent phase.
Draft a policy that outlines general security principles and best practices without specifying granular technical requirements, allowing individual departments to interpret and implement controls as they see fit.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free