nerdexam
EC-Council

712-50 · Question #25

An organization's Information Security Policy is of MOST importance because

The correct answer is A. it communicates management's commitment to protecting information resources. An Information Security Policy derives its primary importance from communicating management's commitment - without visible executive backing, security initiatives lack authority, funding, and organizational buy-in, making everything else downstream ineffective. Option B…

Governance (Policy, Legal & Compliance)

Question

An organization's Information Security Policy is of MOST importance because

Options

  • Ait communicates management's commitment to protecting information resources
  • Bit is formally acknowledged by all employees and vendors
  • Cit defines a process to meet compliance requirements
  • Dit establishes a framework to protect confidential information

How the community answered

(45 responses)
  • A
    76% (34)
  • B
    7% (3)
  • C
    13% (6)
  • D
    4% (2)

Explanation

An Information Security Policy derives its primary importance from communicating management's commitment - without visible executive backing, security initiatives lack authority, funding, and organizational buy-in, making everything else downstream ineffective. Option B (employee/vendor acknowledgment) is a process that flows from the policy, not the reason the policy itself matters. Option C (compliance) is a secondary benefit - policies may address compliance, but compliance is a byproduct, not the core purpose. Option D (protecting confidential information) is too narrow; a good security policy covers all information resources, and "establishing a framework" describes the policy's mechanism, not its fundamental importance.

Memory tip: Think of the policy as a mandate from the top - its power comes from management's voice behind it. Ask yourself: "Why does anyone have to follow this?" The answer is always authority and commitment, not paperwork or frameworks.

Topics

#information security policy#management commitment#governance#risk framework

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice