nerdexam
Isaca

CISA · Question #70

Which of the following is the MOST important factor when an organization is developing information security policies and procedures?

The correct answer is D. Compliance with relevant regulations. When developing information security policies and procedures, the most important factor is ensuring compliance with all relevant regulations, laws, and industry standards.

Submitted by yaw92· Apr 18, 2026Governance and Management of IT

Question

Which of the following is the MOST important factor when an organization is developing information security policies and procedures?

Options

  • AConsultation with security staff
  • BAlignment with an information security framework
  • CInclusion of mission and objectives
  • DCompliance with relevant regulations

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    4% (1)
  • C
    15% (4)
  • D
    74% (20)

Why each option

When developing information security policies and procedures, the most important factor is ensuring compliance with all relevant regulations, laws, and industry standards.

AConsultation with security staff

Consultation with security staff is crucial for practical implementation and technical accuracy, but it serves as a means to achieve compliance and effective security, not the primary driving factor itself.

BAlignment with an information security framework
CInclusion of mission and objectives
DCompliance with relevant regulationsCorrect

Compliance with regulations like HIPAA, GDPR, PCI DSS, or industry-specific mandates is a legal and often financial imperative, as non-compliance can lead to severe fines, legal action, and significant reputational damage. Policies and procedures must therefore be meticulously crafted to meet these binding requirements as a foundational element of an effective information security program.

Concept tested: Info security policy (regulatory compliance)

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

Topics

#Information Security Policies#Compliance#Regulatory Requirements#IT Governance

Community Discussion

No community discussion yet for this question.

Full CISA Practice