Multiple Choice
Which of the following is NOT among the three types of InfoSec policies based on NIST's Special Publication 800-14?
A) Enterprise information security policy
B) User-specific security policies
C) Issue-specific security policies
D) System-specific security policies
Correct Answer:

Verified
Correct Answer:
Verified
Q36: A detailed statement of what must be
Q37: _ include the user access lists,matrices,and capability
Q38: How should a policy administrator facilitate policy
Q39: Policies must specify penalties for unacceptable behavior
Q40: What are the four elements that an
Q42: What is the final component of the
Q43: A section of policy that should specify
Q44: A(n)_,which is usually presented on a screen
Q45: According to NIST SP 800-18,Rev.1,whichindividual is responsible
Q46: What are configuration rules?Provide examples.