nerdexam
(ISC)2

CAP · Question #291

Which of the following is a security policy implemented by an organization due to compliance, regulation, or other legal requirements?

The correct answer is D. Regulatory policy. A regulatory policy is mandated by external laws, regulations, or compliance frameworks (e.g., HIPAA, SOX, PCI-DSS). Organizations must implement these policies or face legal penalties. By contrast, an advisory policy recommends best practices but is not mandatory; an…

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following is a security policy implemented by an organization due to compliance, regulation, or other legal requirements?

Options

  • AAdvisory policy
  • BInformative policy
  • CSystem Security policy
  • DRegulatory policy

How the community answered

(23 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    91% (21)

Explanation

A regulatory policy is mandated by external laws, regulations, or compliance frameworks (e.g., HIPAA, SOX, PCI-DSS). Organizations must implement these policies or face legal penalties. By contrast, an advisory policy recommends best practices but is not mandatory; an informative policy educates employees without imposing requirements; and a system security policy addresses security controls for a specific system rather than being driven by external legal obligations.

Topics

#Security policies#Compliance#Regulatory requirements#Policy types

Community Discussion

No community discussion yet for this question.

Full CAP Practice