Most Important Security Measure for Remote Employees?
An organization provides notebook PCs, cable wire locks, smartphone access, and virtual private network (VPN) access to its remote employees. Which of the following is MOST important for the information security manager to ensure?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests management prioritization over technical implementation, where candidates often mistakenly choose a specific technical control like VPN usage instead of recognizing that comprehensive user training encompasses all other safeguards.
Focuses on Acceptable Use Policy training as the foundational control for remote work security, with community consensus confirming that policy awareness supersedes individual technical safeguards.
Option C (VPNs) is frequently chosen due to its direct technical relevance to remote access, but it overlooks CISM's emphasis on governance, where human compliance via policy training remains the primary managerial responsibility.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In CISM, the information security manager’s primary role is governance and risk management rather than hands-on technical configuration. Training employees on the Acceptable Use Policy (AUP) establishes behavioral expectations that directly govern how they handle devices, networks, and remote access. As noted by top-voted discussions, this single training initiative inherently validates compliance with device locking, VPN usage, and appropriate mobile device practices. Without enforced policy awareness, technical controls alone cannot guarantee secure remote operations.Why the Other Options Are Wrong
Option B suggests smartphone tethering, which actually introduces additional unmanaged network risks and contradicts secure remote access principles. Option C focuses solely on VPN usage, which is a necessary technical control but insufficient without user education on when and how to apply it securely. Option D addresses physical security for notebooks, which is only one component of a broader remote workforce strategy. CISM consistently prioritizes policy-driven human factors over isolated technical or physical measures.Community Comment Notes
Community feedback heavily supports Option A, with multiple users highlighting that AUP training comprehensively covers the remaining options. One contributor explicitly stated that “Option A covers all the B, C, D,” reinforcing the management perspective that policy awareness drives consistent compliance across all provided tools. This aligns with ISACA’s guidance that awareness programs are the foundation of an effective security posture.Official Reference
Exam Strategy
Always prioritize governance, policy, and training answers in CISM questions over technical implementations unless the scenario explicitly describes an immediate crisis requiring technical remediation. Remember that managers oversee processes, not configurations.
Frequently Asked Questions
Why is AUP training prioritized over VPN configuration in CISM?
CISM emphasizes governance and human compliance over technical implementation. Policy training establishes the behavioral framework that dictates proper VPN and device usage.
Does physical PC locking matter more than remote access controls?
Physical security is only one component of a broader strategy. CISM scenarios consistently rank policy awareness higher because it governs both physical and digital safeguards.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →