CISM Certified Information Security Manager – Question1077

What is the BEST way to ensure users comply with organizational security requirements for password complexity?

A.
Include password construction requirements in the security standards
B. Require each user to acknowledge the password requirements
C. Implement strict penalties for user noncompliance
D. Enable system-enforced password configuration

Correct Answer: D

Explanation:

Explanation:
Automated controls are generally more effective in preventing improper actions. Policies and standards provide some deterrence, but are not as effective as automated controls.