あなたがネットワーク管理者であり、会社が従業員の利用規定(AUP)の草案を作成するように依頼したとします。 AUPは情報セキュリティポリシーのどのカテゴリに分類されますか?
正解:D
An Acceptable Use Policy (AUP) is a type of Issue Specific Security Policy (ISSP) that outlines the constraints and practices that users must agree to in order to access the corporate network, endpoints, applications, and the internet. It is designed to provide guidelines for the appropriate use of an organization's IT resources, including employee conduct, data usage, system access privileges, and the handling of confidential information. The AUP is a crucial part of the security policy framework as it directly addresses specific issues related to the acceptable use of IT resources by employees.