nerdexam
EC-Council

312-38 · Question #49

Which of the following policies is used to add additional information about the overall security posture and serves to protect employees and organizations from inefficiency or ambiguity?

The correct answer is C. Issue-Specific Security Policy. An Issue-Specific Security Policy (ISSP) is designed to address particular security concerns or technology areas in detail, giving employees and the organization clear, unambiguous direction on how to handle specific situations - eliminating guesswork and reducing risk from…

Network Security Policy and Management

Question

Which of the following policies is used to add additional information about the overall security posture and serves to protect employees and organizations from inefficiency or ambiguity?

Options

  • AUser policy
  • BIT policy
  • CIssue-Specific Security Policy
  • DGroup policy

How the community answered

(38 responses)
  • B
    3% (1)
  • C
    95% (36)
  • D
    3% (1)

Explanation

An Issue-Specific Security Policy (ISSP) is designed to address particular security concerns or technology areas in detail, giving employees and the organization clear, unambiguous direction on how to handle specific situations - eliminating guesswork and reducing risk from unclear expectations. It supplements broader organizational policies by drilling down into individual topics (e.g., acceptable use of email, remote access, or social media).

Why the distractors are wrong:

  • A. User policy - Not a recognized formal security policy classification; it's too vague and doesn't capture the "additional detail" function described.
  • B. IT policy - A general umbrella term for technology governance; it doesn't specifically fill the role of adding detail to address ambiguity around individual security issues.
  • D. Group policy - This is a technical control (Windows Active Directory configuration), not a security policy document type.

Memory tip: Think of ISSP as the "FAQ" of security policies - when a broad policy leaves gaps, the ISSP steps in with specifics for one issue at a time, protecting everyone from the confusion of "but the policy didn't say anything about this."

Topics

#Security Policy Types#Issue-Specific Policies#Security Posture#Policy Documentation

Community Discussion

No community discussion yet for this question.

Full 312-38 Practice