Question 1 of 30
The recent internal audit has highlighted a significant deficiency in the organization\'s security framework, specifically regarding the establishment and enforcement of clear security policies and procedures across all departments. To address this, the CISO is considering several strategies for developing new security policies. Which of the following approaches is most likely to result in effective, sustainable security policy implementation and compliance?
Establish a cross-functional policy development committee comprising representatives from IT, legal, compliance, HR, and key business units to collaboratively draft and review policies, ensuring alignment with operational needs and regulatory requirements.
Mandate that the IT security team solely develop all new security policies based on industry best practices and then disseminate them to other departments for mandatory adherence.
Engage an external cybersecurity consulting firm to draft a comprehensive set of security policies, with minimal internal input, to ensure an objective and expert-driven approach.
Implement a policy framework that is primarily reactive, focusing on developing or revising policies only after security incidents or audit findings occur.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free