nerdexam
(ISC)2

CGRC · Question #356

Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. Response:

The correct answer is A. Information Security Policy. The question describes a comprehensive set of organizational directives, regulations, rules, and practices governing information management.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. Response:

Options

  • AInformation Security Policy
  • BNational Security System
  • CInformation System Owner
  • DSystem Security Authorization

How the community answered

(20 responses)
  • A
    90% (18)
  • C
    5% (1)
  • D
    5% (1)

Why each option

The question describes a comprehensive set of organizational directives, regulations, rules, and practices governing information management.

AInformation Security PolicyCorrect

An Information Security Policy is a high-level document or set of documents that establishes the overall framework of rules, directives, regulations, and practices an organization employs to manage, protect, and distribute its information assets. It provides the strategic guidance for information security throughout the organization, covering its generation, handling, and disposal. This policy guides all security decisions and actions.

BNational Security System

A National Security System is a type of information system, not a set of policies or rules for information management.

CInformation System Owner

An Information System Owner is a role responsible for a system, not the aggregate of directives and practices themselves.

DSystem Security Authorization

System Security Authorization is a formal management decision to allow a system to operate, rather than the overarching policy that governs information.

Concept tested: Information Security Policy

Source: https://csrc.nist.gov/glossary/term/information_security_policy

Topics

#Information Security Policy#Policy#Governance#Directives

Community Discussion

No community discussion yet for this question.

Full CGRC Practice