I vaguely recall something about the importance of logging and monitoring regardless of scope, which could suggest that yes, they can implement those controls.
Yes, I'm pretty confident that the answer is A. The question specifically states that the systems are not directly in scope of the CSCE, so the Swift user should be able to choose to implement the security controls as they see fit.
Okay, I've got a strategy for this. I'll start by reviewing the CSCE requirements and then consider whether the security controls in question would fall outside of that scope. That should help me determine the right answer.
Hmm, I'm a bit unsure about this one. The question seems to be asking about systems that are not directly covered by the CSCE, but I'm not entirely clear on the implications of that. I'll need to think it through carefully.
I think the key here is to focus on the scope of the CSCE. If the security controls are not directly in scope, then the answer is likely yes, the Swift user can choose to implement them.
Stephen
2 months agoLeslee
2 months agoCarma
3 months agoYolando
3 months agoLai
3 months agoJaney
3 months agoCarolynn
4 months agoEliseo
4 months agoAnnette
4 months agoMalcom
4 months agoJosephine
4 months agoJodi
4 months agoBenedict
5 months agoJovita
6 months ago