SY0-701 - Security Program Management and Oversight - Section 5.1

Summarize elements of effective security governance.

Describe how policies, standards, and procedures form a hierarchy that translates executive direction into operational security behaviour, and how governance structures assign clear roles and responsibilities across the organisation. Recognise how regulatory considerations shape governance requirements, and distinguish the board-level accountability function of governance from the day-to-day management of security operations.

policiesstandards and proceduresgovernance structuresroles and responsibilitiesregulatory considerations

Practice question for this objective

Free sampleSecurity Program Management and Oversightmedium

A regional building society has appointed a compliance lead and must prepare for an external auditor who will judge whether the firm's security compliance programme is effective. The lead has a long list of candidate activities and must distinguish elements that directly evidence effective security compliance from operational security tasks that, while useful, do not by themselves demonstrate compliance to the auditor. Which TWO activities most directly constitute elements of effective security compliance? Select TWO.

  • AProducing a periodic attestation that an independent party signs, formally stating that the in-scope controls were designed and operating effectively across the review window. Correct
  • BOperating a documented data retention schedule that defines how long each record class is kept and triggers verifiable, logged destruction once the legally required period expires. Correct
  • CDeploying an inline intrusion prevention sensor at the perimeter so that known exploit signatures are dropped before they reach the application servers in scope.
  • DRotating the data encryption keys protecting the backup repository every ninety days so that a stolen key cannot decrypt records captured in an earlier window.
  • ERunning a quarterly simulated phishing campaign and publishing the click-through rate so that staff susceptibility is tracked against the previous quarter.
Effective security compliance is evidenced by elements such as attestation and data retention, distinct from operational technical controls and awareness activities. Security compliance is demonstrated through programme elements that produce auditable evidence: attestation gives an independent, signed statement of control effectiveness over a period, and a data retention schedule with logged destruction proves records are held only for the legally required time. Technical controls and awareness exercises support security but do not by themselves evidence compliance.

Why A is correct: Attestation is a named element of effective security compliance: a signed statement of control effectiveness over a period is exactly the independent evidence an external auditor relies on.

Why B is correct: Data retention is a core compliance element; a documented schedule with logged destruction proves the firm holds records only as long as the law allows, which auditors check directly.

Why C is wrong: An IPS is a worthwhile technical mitigation and may sit within scope, but it is an operational control, not an element of the compliance programme itself, so it does not demonstrate compliance.

Why D is wrong: Key rotation is sound cryptographic hygiene and tempting to list, but it is a technical control activity rather than a compliance element such as attestation, reporting, or retention.

Why E is wrong: Phishing simulation belongs to security awareness, not the compliance programme; it measures behaviour and is tempting, but it is not the compliance evidence an auditor assesses.

See more SY0-701 practice questions with worked answers.

More in this domain

Back to all Security Program Management and Oversight objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.