nerdexam
(ISC)2

CGRC · Question #582

A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in…

The correct answer is B. What is being secured? C. Where is the vulnerability, threat, or risk? D. Who is expected to comply with the policy? A well-designed security policy defines what assets are protected, identifies potential risks, and specifies who is responsible for compliance to maintain organizational security.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in a well designed policy? Each correct answer represents a part of the solution. Choose all that apply. Response:

Options

  • AWho is expected to exploit the vulnerability?
  • BWhat is being secured?
  • CWhere is the vulnerability, threat, or risk?
  • DWho is expected to comply with the policy?

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    92% (33)

Why each option

A well-designed security policy defines what assets are protected, identifies potential risks, and specifies who is responsible for compliance to maintain organizational security.

AWho is expected to exploit the vulnerability?

A security policy focuses on protecting assets and defining compliance, not on identifying who might exploit vulnerabilities, as this is a reactive or threat intelligence activity.

BWhat is being secured?Correct

A security policy must explicitly state 'What is being secured,' detailing the assets, data, or systems it aims to protect, which is fundamental to its scope.

CWhere is the vulnerability, threat, or risk?Correct

Addressing 'Where is the vulnerability, threat, or risk?' helps identify critical areas or systems that need specific security measures, informing the policy's implementation strategy.

DWho is expected to comply with the policy?Correct

Clearly stating 'Who is expected to comply with the policy?' ensures that all relevant individuals and groups understand their roles and responsibilities in upholding the policy's guidelines.

Concept tested: Elements of a well-designed security policy

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-12.pdf

Topics

#Security Policy#Policy Elements#Governance#Compliance

Community Discussion

No community discussion yet for this question.

Full CGRC Practice