712-50 · Question #25
An organization's Information Security Policy is of MOST importance because
The correct answer is A. it communicates management's commitment to protecting information resources. An Information Security Policy derives its primary importance from communicating management's commitment - without visible executive backing, security initiatives lack authority, funding, and organizational buy-in, making everything else downstream ineffective. Option B…
Question
An organization's Information Security Policy is of MOST importance because
Options
- Ait communicates management's commitment to protecting information resources
- Bit is formally acknowledged by all employees and vendors
- Cit defines a process to meet compliance requirements
- Dit establishes a framework to protect confidential information
How the community answered
(45 responses)- A76% (34)
- B7% (3)
- C13% (6)
- D4% (2)
Explanation
An Information Security Policy derives its primary importance from communicating management's commitment - without visible executive backing, security initiatives lack authority, funding, and organizational buy-in, making everything else downstream ineffective. Option B (employee/vendor acknowledgment) is a process that flows from the policy, not the reason the policy itself matters. Option C (compliance) is a secondary benefit - policies may address compliance, but compliance is a byproduct, not the core purpose. Option D (protecting confidential information) is too narrow; a good security policy covers all information resources, and "establishing a framework" describes the policy's mechanism, not its fundamental importance.
Memory tip: Think of the policy as a mandate from the top - its power comes from management's voice behind it. Ask yourself: "Why does anyone have to follow this?" The answer is always authority and commitment, not paperwork or frameworks.
Topics
Community Discussion
No community discussion yet for this question.