A regional building society has appointed a compliance lead and must prepare for an external auditor who will judge whether the firm's security compliance programme is effective. The lead has a long list of candidate activities and must distinguish elements that directly evidence effective security compliance from operational security tasks that, while useful, do not by themselves demonstrate compliance to the auditor. Which TWO activities most directly constitute elements of effective security compliance? Select TWO.
- AProducing a periodic attestation that an independent party signs, formally stating that the in-scope controls were designed and operating effectively across the review window. Correct
- BOperating a documented data retention schedule that defines how long each record class is kept and triggers verifiable, logged destruction once the legally required period expires. Correct
- CDeploying an inline intrusion prevention sensor at the perimeter so that known exploit signatures are dropped before they reach the application servers in scope.
- DRotating the data encryption keys protecting the backup repository every ninety days so that a stolen key cannot decrypt records captured in an earlier window.
- ERunning a quarterly simulated phishing campaign and publishing the click-through rate so that staff susceptibility is tracked against the previous quarter.
Why A is correct: Attestation is a named element of effective security compliance: a signed statement of control effectiveness over a period is exactly the independent evidence an external auditor relies on.
Why B is correct: Data retention is a core compliance element; a documented schedule with logged destruction proves the firm holds records only as long as the law allows, which auditors check directly.
Why C is wrong: An IPS is a worthwhile technical mitigation and may sit within scope, but it is an operational control, not an element of the compliance programme itself, so it does not demonstrate compliance.
Why D is wrong: Key rotation is sound cryptographic hygiene and tempting to list, but it is a technical control activity rather than a compliance element such as attestation, reporting, or retention.
Why E is wrong: Phishing simulation belongs to security awareness, not the compliance programme; it measures behaviour and is tempting, but it is not the compliance evidence an auditor assesses.