4.1k views
1 vote
An efficient organization requires the proper alignment of people, processes, and technology. One of the ways good security policies can mitigate this risk is through enforcement. Which of the following situations is an example of enforcement?

1 Answer

5 votes

Answer: an employee is given the authority to request a wire transfer, and a manager is required to approve the transfer .

Options:

  • an employee is requires to submit weekly project updates to a manager .
  • an employee is given the authority to request a wire transfer, and a manager is required to approve the transfer .
  • an employee is given a commendation for successfully complying with policies in an annual review .
  • an employee completes a one-day orientation on security policies .

Step-by-step explanation:

Enforcement

The processes of risk mitigation in an organization starts from defining the risks and designing the systems which will reduce or eliminate the risk.

After identifying the security systems, putting steps in place to enforce them is also very important. When enforcing security policies, it is ideal to have a separation of duties and layers of authorization. Design or the operation should be distinct from the authorization process and should be carried out by different people. Just like in this question, an employee can have the authority to request a wire transfer, but a manager must approve the transfer .

User Zachiah
by
5.5k points