CGRC · Question #698
A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. What are the different types of policies? Each correct…
The correct answer is B. Informative C. Regulatory D. Advisory. Security policies, which are high-level statements from management, can be categorized into several types to guide security practices within an organization. Common policy types include regulatory, advisory, and informative policies, each serving a distinct purpose in…
Question
A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. What are the different types of policies? Each correct answer represents a complete solution. Choose all that apply. Response:
Options
- ASystematic
- BInformative
- CRegulatory
- DAdvisory
How the community answered
(40 responses)- A8% (3)
- B93% (37)
Why each option
Security policies, which are high-level statements from management, can be categorized into several types to guide security practices within an organization. Common policy types include regulatory, advisory, and informative policies, each serving a distinct purpose in establishing security governance.
Systematic is not a standard type of security policy; policies may be systematic in their approach, but it is not a classification category for the policy itself.
Informative policies are designed to educate employees about security requirements and best practices, often without strict enforcement mechanisms. Regulatory policies ensure that the organization complies with external laws, regulations, or industry standards, such as HIPAA or PCI DSS. Advisory policies provide recommendations and guidelines for best practices, offering discretion in their implementation but still promoting secure behavior. These three types - Informative, Regulatory, and Advisory - are widely recognized categories of security policies that organizations adopt to manage their information security posture effectively.
Informative policies are designed to educate employees about security requirements and best practices, often without strict enforcement mechanisms. Regulatory policies ensure that the organization complies with external laws, regulations, or industry standards, such as HIPAA or PCI DSS. Advisory policies provide recommendations and guidelines for best practices, offering discretion in their implementation but still promoting secure behavior. These three types - Informative, Regulatory, and Advisory - are widely recognized categories of security policies that organizations adopt to manage their information security posture effectively.
Informative policies are designed to educate employees about security requirements and best practices, often without strict enforcement mechanisms. Regulatory policies ensure that the organization complies with external laws, regulations, or industry standards, such as HIPAA or PCI DSS. Advisory policies provide recommendations and guidelines for best practices, offering discretion in their implementation but still promoting secure behavior. These three types - Informative, Regulatory, and Advisory - are widely recognized categories of security policies that organizations adopt to manage their information security posture effectively.
Concept tested: Types of security policies
Topics
Community Discussion
No community discussion yet for this question.