A company is establishing operational guidelines to meet compliance mandates for its core data facility. The chief security officer highlights the necessity of administrative safeguards working in tandem with physical access mechanisms. Which initiative is properly classified as an administrative element of a security program?
- Mandating quarterly security awareness training sessions and formal clean-desk policies for all staffCevap
- BDeploying biometric fingerprint readers and mantrap vestibules at the entrance of the data hall
- CConfiguring centralized AAA server authentication with TACACS+ to govern access to network switch consoles
- DImplementing dynamic port security on access switches to shut down ports upon unauthorized MAC detection
Cevap
Mandating quarterly security awareness training sessions and formal clean-desk policies for all staff is an administrative security program element.
The option specifying mandatory security awareness training and clean-desk policies represents an administrative security control. Administrative controls consist of policies, regulations, compliance guidelines, and security awareness programs designed to direct human behavior and govern organizational security operations.
Adım Adım Çözüm
Anahtar Kavram
Classification of Security Program Elements (Administrative vs. Physical vs. Technical Controls)
Tahmini Süre:1m 0s