nerdexam
Isaca

CISA · Question #440

Once a security policy is approved by key stakeholders, the NEXT step should be to:

The correct answer is D. integrate it into the security awareness program. After formal approval, a security policy must be communicated and embedded into organizational culture, typically through awareness training, so that all employees understand and adhere to its

Submitted by deeparc· Apr 18, 2026Governance and Management of IT

Question

Once a security policy is approved by key stakeholders, the NEXT step should be to:

Options

  • Aupdate it according to schedule
  • Bshare it with external auditors
  • Cvalidate it against security standards
  • Dintegrate it into the security awareness program

How the community answered

(64 responses)
  • A
    5% (3)
  • B
    8% (5)
  • C
    16% (10)
  • D
    72% (46)

Explanation

After formal approval, a security policy must be communicated and embedded into organizational culture, typically through awareness training, so that all employees understand and adhere to its

Topics

#Security Policy#Policy Implementation#Security Awareness#IT Governance

Community Discussion

No community discussion yet for this question.

Full CISA Practice