712-50 Question 271
Single answerIdentify standards, procedures, directives, policies, regulations, and laws for physical securityA multinational company is consolidating physical security requirements for a new regional data center that will process payment card transactions, store employee records, and operate in a jurisdiction with strict workplace safety and privacy laws. During a governance review, the Chief Information Security Officer finds that site managers are relying on a mix of local practices, vendor guidance, and informal instructions to control visitor access, badge issuance, CCTV retention, and server room entry. Which action should the CISO take FIRST to create a defensible and compliant physical security framework across the site?
- A
Develop a hierarchical governance structure that maps applicable laws and regulations to corporate physical security policies, then define supporting standards, procedures, and site directives for implementation
- B
Adopt the physical security controls recommended by the access control vendor because they reflect current industry practices and can be implemented quickly
- C
Instruct each facility manager to document current local physical security practices and continue operating them until an external audit identifies gaps
- D
Publish a single enterprise procedure for badge access, CCTV, and visitor handling without first distinguishing between mandatory legal requirements and internal policy choices
Show answer and explanation
Correct answer: A
Explanation
This question tests the candidate's ability to distinguish and properly sequence laws, regulations, policies, standards, procedures, and directives in a physical security program. In a CCISO context, the first step is not selecting tools or documenting current habits, but establishing the governance foundation: determine applicable external requirements such as privacy law, workplace safety law, sector-specific obligations, and contractual mandates; then convert those obligations into internal policy statements. From there, standards define required control baselines, procedures describe operational steps, and local directives or work instructions tailor implementation to the site.
This hierarchy is consistent with common governance practice and industry frameworks. For example, ISO/IEC 27001 and ISO/IEC 27002 expect organizations to identify applicable legal, statutory, regulatory, and contractual requirements and incorporate them into the information security management system. NIST guidance also distinguishes between policy-level direction and procedure-level implementation. For physical security specifically, organizations commonly map requirements from applicable law, employment/privacy rules, health and safety obligations, and industry frameworks such as PCI DSS physical access controls before finalizing site procedures. A defensible physical security program must therefore start with identifying and structuring obligations correctly, not with ad hoc practices or vendor-led implementation.
- A. Correct.
Correct. A CISO should first establish a governance hierarchy: identify external obligations such as laws, regulations, and contractual requirements; translate them into enterprise policies; and then issue standards, procedures, and local directives that implement those requirements consistently. This is the most defensible approach because it distinguishes what is legally mandatory from what is internally mandated, and it supports auditability, accountability, and consistent enforcement across sites.
- B. Incorrect.
Incorrect. Vendor guidance can be useful input, but it is not a substitute for identifying applicable laws, regulations, corporate policy requirements, and internal governance obligations. A vendor's recommendations may not address local privacy laws, workplace safety rules, employment requirements, or industry obligations such as payment card physical access restrictions. Choosing controls solely based on vendor guidance is a common governance mistake.
- C. Incorrect.
Incorrect. Documenting current practices may help with gap analysis, but allowing sites to continue informal approaches until an audit occurs is reactive and weak from a governance perspective. The CISO's responsibility is to proactively identify and align physical security requirements, not wait for auditors to discover inconsistencies or noncompliance.
- D. Incorrect.
Incorrect. A single enterprise procedure without first identifying legal, regulatory, and policy drivers can create conflicts with local laws and may omit mandatory controls. Procedures describe how to perform tasks; they should derive from policies and standards, which in turn should reflect applicable laws, regulations, and business obligations. Skipping that hierarchy is a common misconception.