nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #319

In an organization, which document provides step-by-step guidance in implementing a security measure?

The correct answer is D. Procedures. Procedures provide detailed, step-by-step instructions for implementing specific security measures or tasks. They are the most granular level of security documentation. Policies (B) are high-level statements of intent and management direction (e.g., 'all data must be…

Security Principles

Question

In an organization, which document provides step-by-step guidance in implementing a security measure?

Options

  • AStandards
  • BPolicies
  • CRegulations
  • DProcedures

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    3% (1)
  • D
    86% (31)

Explanation

Procedures provide detailed, step-by-step instructions for implementing specific security measures or tasks. They are the most granular level of security documentation. Policies (B) are high-level statements of intent and management direction (e.g., 'all data must be encrypted'). Standards (A) define specific mandatory requirements (e.g., 'use AES-256 encryption'). Regulations (C) are external legal or government mandates. The hierarchy flows from Policy → Standard → Procedure, with procedures being the actionable, how-to documents.

Topics

#Security Documentation#Procedures#Security Governance#Implementation Guidance

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice