Question 1
Review the following compliance obligation: The organization must block all unnecessary egress firewall traffic AND maintain a web/url filtering device OR block all outbound user web traffic. How many obligations are required in this scenario?
1
2
3
4
Question 2
You have noted the following compliance obligation: "If your organization experiences a significant security breach, you must notify the Client within 24 hours of discovery." This is the only thing left to hammer our with respect to this client. Which of the following is the most prudent advice if further negotiating with the Client is not possible?
Suggest that the client goes elsewhere
Since there is no negotiation, agree to the terms
Try to reach a common understanding of the word significant and develop a notification process
Agree with the terms and allow other stakeholders to take the lead on sorting out the remaining details
Next Concept