Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 20

As the Chief Information Security Officer (CISO) of a multinational corporation, you are overseeing the implementation of a new company-wide security framework. You must ensure that the protection profile of each system matches the sensitivity of the data it handles. Which approach should you take to align the standard to the unique security requirements of various departments within your organization?
  • A Only implement the most stringent controls in the standard, ensuring maximum security.
  • B Impose a uniform standard across all departments, regardless of their specific needs.
  • C Leverage tailoring to adjust the standard according to the needs of each department.
  • D Adopt different standards for each department, completely disregarding any uniformity.
Reveal correct answer

Correct answer: C

Explanation

The correct answer: Tailoring allows the organization to adjust the standard to meet the unique security requirements of each department. This approach ensures that the right level of security controls is applied where needed, optimizing the use of resources and maintaining an appropriate level of security across the organization. Tailoring allows for a balance between uniformity and customization, making it the most effective approach in this scenario. The incorrect answers: Uniformity simplifies the implementation and management of security controls, but it may not adequately address the unique risk profiles of different departments. Some departments may handle more sensitive data than others, necessitating stricter controls. Imposing a uniform standard may also result in unnecessary costs and complexity in departments that handle less sensitive data. Adopting different standards for each department, completely disregarding any uniformity addresses the unique needs of each department, but it may create inconsistencies and complexities in the overall security posture of the organization. Implementing disparate standards could also lead to management difficulties, regulatory compliance challenges, and interoperability issues between different departments. Only implementing the most stringent controls in the standard, ensuring maximum security may seem to provide the highest level of security, but it's not always the most effective or efficient method. Some of the most stringent controls may not be necessary depending on the nature of the data and the associated risks. This approach could result in wasted resources, increased complexity, and potential user resistance due to overly restrictive controls.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need