nerdexam
EC-Council

712-50 · Question #33

According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?

The correct answer is D. Define Information Security Policy. Defining the Information Security Policy (D) must come first because it establishes the organization's intent, direction, and commitment to information security - it is the foundational document that gives meaning and authority to every subsequent governance activity under ISO…

Governance (Policy, Legal & Compliance)

Question

According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?

Options

  • AIdentify threats, risks, impacts and vulnerabilities
  • BDecide how to manage risk
  • CDefine the budget of the Information Security Management System
  • DDefine Information Security Policy

How the community answered

(23 responses)
  • A
    13% (3)
  • B
    4% (1)
  • C
    9% (2)
  • D
    74% (17)

Explanation

Defining the Information Security Policy (D) must come first because it establishes the organization's intent, direction, and commitment to information security - it is the foundational document that gives meaning and authority to every subsequent governance activity under ISO 27001.

Why the distractors are wrong:

  • A (Identify threats, risks, impacts, and vulnerabilities) - Risk identification is part of the risk assessment process, which happens after the policy is set, because the policy defines what assets and objectives are worth protecting.
  • B (Decide how to manage risk) - Risk treatment decisions come after you've assessed risks, which itself comes after the policy is established. This is several steps downstream.
  • C (Define the budget) - Budget allocation is a planning/resource activity that follows policy definition; you can't meaningfully budget for security without first knowing what your security objectives are.

Memory tip: Think of the policy as the organization's "security constitution" - just as a constitution must exist before laws or enforcement mechanisms, the Information Security Policy must exist before you can meaningfully identify risks, treat them, or fund them. Policy → Risk Assessment → Risk Treatment → Resources.

Topics

#ISO 27001#Information Security Governance#Information Security Policy#Risk Management

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice