QuestionQ107

Information Security Governance

A data-hosting organization’s data center contains servers, applications, and data for many geographically distributed customers. Which of the following strategies is the BEST approach for developing the organization’s physical access control policy?

  • A Review customers’ security policies.
  • B Design single sign-on (SSO) or federated access.
  • C Develop access control requirements for each system and application.
  • D Conduct a risk assessment to determine security risks and mitigating controls.
Explanation

A risk assessment identifies relevant physical security threats, vulnerabilities, business impacts, and appropriate mitigating controls. Those results provide the risk-based basis for a physical access control policy.

Community Discussion

No comments yet. Be the first to start the discussion!