colemic wrote: » ...but if management doesn't buy in and support the policies, then they won't be implemented.
instant000 wrote: » first question, was about BEST detecting intrusion. Only the D choice does that. Nothing else really monitors anything. Intrusion detection requires something to occur, and something to respond to that occurring. second question was about MOST critical for successful while it can be argued that management approval is usually recommended for everything security related, that would have been a good answer, except for this: the other choice said ALL parties, which meant everyone would participate. As we all know that security is not any stronger than its weakest link, getting everyone on board would be MOST critical, as "ALL" would have to include Management also., whereas only Management would exclude the workers who would be subject to the policy As you have a CISSP, and have other security experience, then you are correct that Management's approval is a very critical factor for accomplishing most anything security related. (It's a "theme" you develop, as you read the material, LOL. But, you must also agree that, logically, "All" includes both management and the end user community. I think this question was posed to make you think, and make sure to choose the "BEST" answer. Like JDMurray, that term "assimilate" bothers me. Makes me think of the "Borg". Is that how the term is phrased in your corresponding preparation materials: "assimilate"?