nerdexam
(ISC)2

CAP · Question #252

A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. What are the different types of policies? Each correct…

The correct answer is B. Regulatory C. Advisory D. Informative. Security policies fall into three standard types: Regulatory (B) - policies required by law or industry regulation (e.g., HIPAA, PCI-DSS compliance mandates); Advisory (C) - policies that strongly recommend practices but are not strictly mandatory, guiding behavior without…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. What are the different types of policies? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ASystematic
  • BRegulatory
  • CAdvisory
  • DInformative

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    88% (21)

Explanation

Security policies fall into three standard types: Regulatory (B) - policies required by law or industry regulation (e.g., HIPAA, PCI-DSS compliance mandates); Advisory (C) - policies that strongly recommend practices but are not strictly mandatory, guiding behavior without legal force; and Informative (D) - policies that simply provide information or education to employees without mandating or recommending specific actions. 'Systematic' (A) is not a recognized category of security policy in standard frameworks.

Topics

#Security Policy Types#Policy Classification#Regulatory Policies#Advisory Policies

Community Discussion

No community discussion yet for this question.

Full CAP Practice