712-50 · Question #320
An organization information security policy serves to
The correct answer is B. establish acceptable systems and user behavior. An organization's information security policy operates at the strategic/governance level - it defines what is acceptable behavior for systems and users, setting the "rules of the road" for the entire organization. This makes B correct because policy is about intent and…
Question
An organization information security policy serves to
Options
- Aestablish budgetary input in order to meet compliance requirements
- Bestablish acceptable systems and user behavior
- Cdefine security configurations for systems
- Ddefine relationships with external law enforcement agencies
How the community answered
(23 responses)- A13% (3)
- B74% (17)
- C9% (2)
- D4% (1)
Explanation
An organization's information security policy operates at the strategic/governance level - it defines what is acceptable behavior for systems and users, setting the "rules of the road" for the entire organization. This makes B correct because policy is about intent and boundaries, not technical implementation details.
Why the distractors are wrong:
- A - Budgetary planning stems from policy requirements but is not what the policy itself establishes; that's a finance/compliance planning function.
- C - Specific security configurations belong in standards and procedures (lower-tier documents), not the high-level policy itself.
- D - Relationships with law enforcement may appear in incident response plans or legal agreements, not the information security policy.
Memory tip: Think of the policy hierarchy as PPP - Policy → Procedure → Practice. Policy is always the broadest, most abstract layer ("what we will and won't allow"), while the more specific how-to details live in the documents below it.
Topics
Community Discussion
No community discussion yet for this question.