712-50 Question 270
Single answerIdentify standards, procedures, directives, policies, regulations, and laws for physical securityA global financial services company is opening a new regional office that will include an on-site server room, badge-controlled entry points, CCTV coverage, and a reception area that processes visitor identification. The CCISO has been asked to establish the governing documentation for physical security before local implementation begins. The company already has an enterprise information security policy but no detailed physical security documentation for this location. Which document should the CCISO require to be created FIRST to provide management direction and a basis for consistent physical security standards, procedures, and enforcement across the site?
- A
A site-level physical security policy approved by management that defines objectives, scope, roles, and compliance requirements
- B
A step-by-step visitor escort procedure written by the local facilities supervisor
- C
A security guard post order describing patrol times, incident escalation, and key control activities
- D
A technical standard for CCTV camera retention periods and badge reader log settings
Show answer and explanation
Correct answer: A
Explanation
In a governance hierarchy, policy comes before standards, procedures, and directives. A CCISO is expected to ensure that physical security is governed by management-approved policy that sets expectations and accountability, especially where physical access controls, surveillance, visitor processing, and protection of information assets are involved. Once policy is established, the organization can create standards such as badge control requirements, CCTV retention baselines, and server room protection measures; procedures such as visitor registration and escort workflows; and directives or post orders for guards and reception personnel.
This approach aligns with common security governance practices reflected in ISO/IEC 27001 and ISO/IEC 27002, which require organizations to define policies and supporting controls, including physical and environmental security. It also supports compliance mapping to regulations and laws where applicable, such as privacy obligations related to CCTV and visitor ID records, workplace safety requirements, and sector-specific expectations for protecting facilities that process sensitive data. The key exam point is distinguishing the role of policy as the foundation from lower-level documents that operationalize it.
- A. Correct.
Correct. A policy is the highest-level governing document in this scenario and should be established first because it provides management intent, scope, accountability, and the authority for subordinate standards, procedures, and directives. For physical security, this would address areas such as access control expectations, visitor handling, monitoring, asset protection, and regulatory obligations. Without an approved policy, site standards and procedures may be inconsistent, unenforceable, or misaligned with business and legal requirements.
- B. Incorrect.
Incorrect. A visitor escort procedure is important, but procedures are implementation-level documents that describe how staff perform a task. They should be derived from policy and supporting standards. Creating procedures first risks local practices being developed without management-approved objectives or alignment to enterprise governance.
- C. Incorrect.
Incorrect. Guard post orders are directive or operational instruction documents used to guide daily execution by security personnel. They are narrower than policy and are typically based on established policy, standards, and procedures. Writing post orders first would address operational detail before governance and compliance requirements are defined.
- D. Incorrect.
Incorrect. A technical standard for CCTV retention and badge reader logging is necessary for consistency and auditability, especially in regulated environments, but standards should be created under the authority of policy. Defining technical settings before establishing policy can result in controls that are not traceable to business requirements, legal obligations, or risk appetite.