nerdexam
EC-Council

312-50V10 · Question #280

A security policy will be more accepted by employees if it is consistent and has the support of

The correct answer is B. executive management.. Security policies gain the broadest organizational acceptance when they carry visible, top-down support from executive management, because that authority compels compliance across all levels.

Information Security and Ethical Hacking Fundamentals

Question

A security policy will be more accepted by employees if it is consistent and has the support of

Options

  • Acoworkers.
  • Bexecutive management.
  • Cthe security officer.
  • Da supervisor.

How the community answered

(56 responses)
  • A
    4% (2)
  • B
    93% (52)
  • C
    2% (1)
  • D
    2% (1)

Why each option

Security policies gain the broadest organizational acceptance when they carry visible, top-down support from executive management, because that authority compels compliance across all levels.

Acoworkers.

Coworkers have no formal authority to mandate policy compliance, making peer influence insufficient on its own.

Bexecutive management.Correct

Executive management holds organizational authority over all employees and departments. When a security policy is visibly championed and enforced by executives, it signals that compliance is a business priority and carries consequences, which drives adoption far more effectively than peer or mid-level endorsement. This is a foundational principle in security governance frameworks such as ISO 27001 and NIST SP 800-53.

Cthe security officer.

The security officer is responsible for creating and advocating policies but typically lacks the organizational authority to compel compliance enterprise-wide.

Da supervisor.

A supervisor has authority only over their direct reports, limiting the policy's reach and enforceability across the broader organization.

Concept tested: Security policy governance and executive sponsorship

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#security policy#executive management#top-down approach#organizational security

Community Discussion

No community discussion yet for this question.

Full 312-50V10 Practice