CERTIFIED-IN-CYBERSECURITY · Question #338
To ensure cybersecurity practices remain effective, which documents should be regularly updated and reviewed?
The correct answer is A. Policies. Policies must be regularly reviewed and updated because they define the organization's security intent and strategic direction. As the threat landscape evolves, new technologies are adopted, regulations change, and business objectives shift, policies must be revised to remain…
Question
To ensure cybersecurity practices remain effective, which documents should be regularly updated and reviewed?
Options
- APolicies
- BRegulations
- CStandards
- DProcedures
How the community answered
(22 responses)- A95% (21)
- C5% (1)
Explanation
Policies must be regularly reviewed and updated because they define the organization's security intent and strategic direction. As the threat landscape evolves, new technologies are adopted, regulations change, and business objectives shift, policies must be revised to remain relevant and effective. Regulations are external laws and cannot be changed by the organization. Standards and procedures also need periodic updates, but policies sit at the top of the governance hierarchy - if a policy is outdated, all supporting documents beneath it may also be misaligned with current security needs.
Topics
Community Discussion
No community discussion yet for this question.