312-38 · Question #49
Which of the following policies is used to add additional information about the overall security posture and serves to protect employees and organizations from inefficiency or ambiguity?
The correct answer is C. Issue-Specific Security Policy. An Issue-Specific Security Policy (ISSP) is designed to address particular security concerns or technology areas in detail, giving employees and the organization clear, unambiguous direction on how to handle specific situations - eliminating guesswork and reducing risk from…
Question
Options
- AUser policy
- BIT policy
- CIssue-Specific Security Policy
- DGroup policy
How the community answered
(38 responses)- B3% (1)
- C95% (36)
- D3% (1)
Explanation
An Issue-Specific Security Policy (ISSP) is designed to address particular security concerns or technology areas in detail, giving employees and the organization clear, unambiguous direction on how to handle specific situations - eliminating guesswork and reducing risk from unclear expectations. It supplements broader organizational policies by drilling down into individual topics (e.g., acceptable use of email, remote access, or social media).
Why the distractors are wrong:
- A. User policy - Not a recognized formal security policy classification; it's too vague and doesn't capture the "additional detail" function described.
- B. IT policy - A general umbrella term for technology governance; it doesn't specifically fill the role of adding detail to address ambiguity around individual security issues.
- D. Group policy - This is a technical control (Windows Active Directory configuration), not a security policy document type.
Memory tip: Think of ISSP as the "FAQ" of security policies - when a broad policy leaves gaps, the ISSP steps in with specifics for one issue at a time, protecting everyone from the confusion of "but the policy didn't say anything about this."
Topics
Community Discussion
No community discussion yet for this question.