A network security policy defines the scope of security measures within an organization’s network. It sets the rules for behavior, outlines acceptable use, identifies protected resources, defines responses to security breaches, and lays out disciplinary measures for violations.
Physical security (A) focuses on tangible access control.
Forensic investigations (C) deal with post-incident evidence gathering.
Spam filtering (D) is a specific technical control, not a policy framework.
[References:, , ASIS POA Manual – Information Security Governance, , PSP Study Guide – Policy Development and Enforcement]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit