CGRC · Question #356
Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. Response:
The correct answer is A. Information Security Policy. The question describes a comprehensive set of organizational directives, regulations, rules, and practices governing information management.
Question
Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. Response:
Options
- AInformation Security Policy
- BNational Security System
- CInformation System Owner
- DSystem Security Authorization
How the community answered
(20 responses)- A90% (18)
- C5% (1)
- D5% (1)
Why each option
The question describes a comprehensive set of organizational directives, regulations, rules, and practices governing information management.
An Information Security Policy is a high-level document or set of documents that establishes the overall framework of rules, directives, regulations, and practices an organization employs to manage, protect, and distribute its information assets. It provides the strategic guidance for information security throughout the organization, covering its generation, handling, and disposal. This policy guides all security decisions and actions.
A National Security System is a type of information system, not a set of policies or rules for information management.
An Information System Owner is a role responsible for a system, not the aggregate of directives and practices themselves.
System Security Authorization is a formal management decision to allow a system to operate, rather than the overarching policy that governs information.
Concept tested: Information Security Policy
Source: https://csrc.nist.gov/glossary/term/information_security_policy
Topics
Community Discussion
No community discussion yet for this question.