CAP · Question #291
Which of the following is a security policy implemented by an organization due to compliance, regulation, or other legal requirements?
The correct answer is D. Regulatory policy. A regulatory policy is mandated by external laws, regulations, or compliance frameworks (e.g., HIPAA, SOX, PCI-DSS). Organizations must implement these policies or face legal penalties. By contrast, an advisory policy recommends best practices but is not mandatory; an…
Question
Which of the following is a security policy implemented by an organization due to compliance, regulation, or other legal requirements?
Options
- AAdvisory policy
- BInformative policy
- CSystem Security policy
- DRegulatory policy
How the community answered
(23 responses)- A4% (1)
- C4% (1)
- D91% (21)
Explanation
A regulatory policy is mandated by external laws, regulations, or compliance frameworks (e.g., HIPAA, SOX, PCI-DSS). Organizations must implement these policies or face legal penalties. By contrast, an advisory policy recommends best practices but is not mandatory; an informative policy educates employees without imposing requirements; and a system security policy addresses security controls for a specific system rather than being driven by external legal obligations.
Topics
Community Discussion
No community discussion yet for this question.