nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #409

What does a well-designed security policy aim to achieve?

The correct answer is B. Reduce the potential of security breaches to an acceptable level. No security policy can eliminate all risk entirely. The realistic and accepted goal of a well-designed security policy is to reduce the likelihood and impact of security breaches to a level that is acceptable to the organization - this is the concept of residual risk. Options A…

Security Principles

Question

What does a well-designed security policy aim to achieve?

Options

  • AReduce the cost of system operations
  • BReduce the potential of security breaches to an acceptable level
  • CIncrease the potential of security breaches
  • DReduce the complexity of the system

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    86% (25)
  • C
    7% (2)
  • D
    3% (1)

Explanation

No security policy can eliminate all risk entirely. The realistic and accepted goal of a well-designed security policy is to reduce the likelihood and impact of security breaches to a level that is acceptable to the organization - this is the concept of residual risk. Options A and D (reducing cost or complexity) are secondary benefits, not primary goals. Option C (increasing breaches) is the opposite of what a policy aims to do.

Topics

#Security Policy#Risk Management#Security Goals#Information Security Principles

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice