ExamQuestions.com

Register
Login
Certified Secure Software Lifecycle Professional (CSSLP) Exam Questions

ISC

Certified Secure Software Lifecycle Professional (CSSLP)

70 / 190

Question 70:

A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in a well designed policy? Each correct answer represents a part of the solution. Choose all that apply. 

Answer options:

A. What is being secured?
B. Where is the vulnerability, threat, or risk?
C. Who is expected to exploit the vulnerability?
D. Who is expected to comply with the policy?