Study ISC2 CC best-practice security policies and awareness training: data handling, passwords, AUP, BYOD, change management, privacy, and social engineering.
Security policies and awareness training turn security expectations into repeatable behavior. CC questions often test whether the answer improves behavior, reduces risky actions, or defines the correct process.
| Policy | What it controls |
|---|---|
| Data handling | classification, storage, sharing, retention, disposal |
| Password | creation, reuse, rotation or change triggers, MFA alignment |
| Acceptable Use Policy | permitted use of company systems |
| BYOD | personal-device access, security requirements, support boundaries |
| Change management | documentation, approval, testing, rollback |
| Privacy | personal-data handling and legal/organizational obligations |
| Topic | Exam-safe behavior |
|---|---|
| Phishing | report through approved channel, do not click or forward broadly |
| Social engineering | verify identity and follow procedure |
| Password protection | use approved password/MFA practices and do not share credentials |
| AI tools | do not paste sensitive data into unapproved public tools |
| Incident reporting | report quickly, preserve evidence, and avoid unauthorized investigation |
The best policy/training answer usually combines:
Awareness without policy is weak. Policy without training and evidence is also weak.