Wednesday, 20 December 2017

CISSP Question Answer

Which one of the following should NOT be contained within a computer policy?

A. Definition of management expectations.
B. Responsibilities of individuals and groups for protected information.
C. Statement of senior executive support.
D. Definition of legal and regulatory controls.

Answer: B

Which one of the following is NOT a fundamental component of a Regulatory Security Policy?

A. What is to be done.
B. When it is to be done.
C. Who is to do it.
D. Why is it to be done

Answer: C

