nerdexam
(ISC)2

CCSP · Question #780

Every security program and process should have which of the following?

The correct answer is C. Foundational policy. Policy drives all programs and functions in the organization; the organization should not conduct any operations that don't have a policy governing them. Penalties may or may not be an element of policy, and severity depends on the topic. Multifactor authentication and homomorphi

Submitted by certguy· Apr 18, 2026Legal, Risk and Compliance

Question

Every security program and process should have which of the following?

Options

  • ASevere penalties
  • BMultifactor authentication
  • CFoundational policy
  • DHomomorphic encryption

How the community answered

(19 responses)
  • A
    5% (1)
  • C
    95% (18)

Explanation

Policy drives all programs and functions in the organization; the organization should not conduct any operations that don't have a policy governing them. Penalties may or may not be an element of policy, and severity depends on the topic. Multifactor authentication and homomorphic encryption are red herrings here.

Topics

#Security Policy#Security Governance#Risk Management#Compliance

Community Discussion

No community discussion yet for this question.

Full CCSP Practice