CISM · Question #132
Which of the following is MOST important to include in an enterprise information security policy?
The correct answer is B. Security objectives. Security objectives establish the purpose and strategic direction of the entire information security program. They define what the organization intends to achieve and provide the foundation from which all other policy elements, procedures, and controls are derived. Without object
Question
Which of the following is MOST important to include in an enterprise information security policy?
Options
- AAcceptable use
- BSecurity objectives
- CSecurity metrics
- DAudit trail review requirements
How the community answered
(33 responses)- A6% (2)
- B88% (29)
- C3% (1)
- D3% (1)
Explanation
Security objectives establish the purpose and strategic direction of the entire information security program. They define what the organization intends to achieve and provide the foundation from which all other policy elements, procedures, and controls are derived. Without objectives, a policy lacks meaning and measurability. Acceptable use (A) is an operational directive. Security metrics (C) measure progress toward objectives-they cannot exist without first having objectives defined. Audit trail review requirements (D) are a procedural control that stems from objectives around accountability and monitoring.
Topics
Community Discussion
No community discussion yet for this question.