nerdexam
EC-Council

312-50V9 · Question #607

Every company needs a formal written document which spells out to employees precisely what they are allowed to use the company's systems for, what is prohibited, and what will happen to them if they…

The correct answer is B. Information Security Policy (ISP). The document described is an Information Security Policy, which is the foundational governance document defining acceptable use, prohibited activities, and enforcement consequences for employees.

Introduction to Ethical Hacking

Question

Every company needs a formal written document which spells out to employees precisely what they are allowed to use the company's systems for, what is prohibited, and what will happen to them if they break the rules. Two printed copies of the policy should be given to every employee as soon as possible after they join the organization. The employee should be asked to sign one copy, which should be safely filed by the company. No one should be allowed to use the company's computer systems until they have signed the policy in acceptance of its terms. What is this document called?

Options

  • AInformation Audit Policy (IAP)
  • BInformation Security Policy (ISP)
  • CPenetration Testing Policy (PTP)
  • DCompany Compliance Policy (CCP)

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    93% (28)
  • D
    3% (1)

Why each option

The document described is an Information Security Policy, which is the foundational governance document defining acceptable use, prohibited activities, and enforcement consequences for employees.

AInformation Audit Policy (IAP)

An Information Audit Policy governs the periodic review and assessment of information assets, not the day-to-day acceptable use rules for employees.

BInformation Security Policy (ISP)Correct

An Information Security Policy (ISP) is the formal organizational document that communicates rules for acceptable use of IT systems, explicitly lists prohibited behaviors, and defines the disciplinary consequences for violations. It is a core requirement of security governance frameworks such as ISO 27001 and NIST SP 800-12. Requiring employees to sign and acknowledge the ISP before system access establishes legal and organizational accountability.

CPenetration Testing Policy (PTP)

A Penetration Testing Policy defines the authorized scope, rules of engagement, and procedures for security testing - it does not address general employee use of company systems.

DCompany Compliance Policy (CCP)

Company Compliance Policy is not a recognized standard security document category and does not specifically govern employee IT system use or spell out consequences for violations.

Concept tested: Information Security Policy definition and purpose

Source: https://csrc.nist.gov/publications/detail/sp/800-12/rev-1/final

Topics

#security policy#acceptable use policy#information security policy#compliance

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice