Most Important Security Measure for Remote Employees?

Security Governance & Awareness
Answer Correct answer: A — Ensure employees receive comprehensive training on the acceptable use policy to govern secure remote device and network usage.

An organization provides notebook PCs, cable wire locks, smartphone access, and virtual private network (VPN) access to its remote employees. Which of the following is MOST important for the information security manager to ensure?

  1. Employees are trained on the acceptable use policy. Correct Answer
  2. Employees use smartphone tethering when accessing from remote locations.
  3. Employees use the VPN when accessing the organization's online resources.
  4. Employees physically lock PCs when leaving the immediate area.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests management prioritization over technical implementation, where candidates often mistakenly choose a specific technical control like VPN usage instead of recognizing that comprehensive user training encompasses all other safeguards.

Focuses on Acceptable Use Policy training as the foundational control for remote work security, with community consensus confirming that policy awareness supersedes individual technical safeguards.

Option C (VPNs) is frequently chosen due to its direct technical relevance to remote access, but it overlooks CISM's emphasis on governance, where human compliance via policy training remains the primary managerial responsibility.

Community Discussion (4 comments)

Booict 👍 2
C - Use the VPN when accessing the organization’s online resources is crucial. VPNs encrypt communication, ensuring confidentiality and secure access. This directly mitigates risks associated with remote connections. Option A is it is not the most critical concern when providing remote access to employees. Acceptable use policies cover general guidelines, but they don’t directly address the security of remote connections.
afoo1314 👍 3 Selected: A
Option A cover all the B, C, D.
oluchecpoint 👍 1 Selected: A
Acceptable use policy
yottabyte 👍 2 Selected: A
All options are important but A will cover the remaining options.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In CISM, the information security manager’s primary role is governance and risk management rather than hands-on technical configuration. Training employees on the Acceptable Use Policy (AUP) establishes behavioral expectations that directly govern how they handle devices, networks, and remote access. As noted by top-voted discussions, this single training initiative inherently validates compliance with device locking, VPN usage, and appropriate mobile device practices. Without enforced policy awareness, technical controls alone cannot guarantee secure remote operations.

Why the Other Options Are Wrong

Option B suggests smartphone tethering, which actually introduces additional unmanaged network risks and contradicts secure remote access principles. Option C focuses solely on VPN usage, which is a necessary technical control but insufficient without user education on when and how to apply it securely. Option D addresses physical security for notebooks, which is only one component of a broader remote workforce strategy. CISM consistently prioritizes policy-driven human factors over isolated technical or physical measures.

Community Comment Notes

Community feedback heavily supports Option A, with multiple users highlighting that AUP training comprehensively covers the remaining options. One contributor explicitly stated that “Option A covers all the B, C, D,” reinforcing the management perspective that policy awareness drives consistent compliance across all provided tools. This aligns with ISACA’s guidance that awareness programs are the foundation of an effective security posture.

Official Reference

Exam Strategy

Always prioritize governance, policy, and training answers in CISM questions over technical implementations unless the scenario explicitly describes an immediate crisis requiring technical remediation. Remember that managers oversee processes, not configurations.

Frequently Asked Questions

Why is AUP training prioritized over VPN configuration in CISM?

CISM emphasizes governance and human compliance over technical implementation. Policy training establishes the behavioral framework that dictates proper VPN and device usage.

Does physical PC locking matter more than remote access controls?

Physical security is only one component of a broader strategy. CISM scenarios consistently rank policy awareness higher because it governs both physical and digital safeguards.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide