CISM · Question #302
Information security policies should PRIMARILY reflect alignment with:
The correct answer is D. senior management intent. Information security policies exist to translate organizational goals and risk appetite into actionable rules, so they must first and foremost reflect senior management intent - the people accountable for the organization's direction, risk tolerance, and resource allocation…
Question
Information security policies should PRIMARILY reflect alignment with:
Options
- Adata security standards.
- Bindustry best practices.
- Can information security framework.
- Dsenior management intent.
How the community answered
(35 responses)- A3% (1)
- B3% (1)
- D94% (33)
Explanation
Information security policies exist to translate organizational goals and risk appetite into actionable rules, so they must first and foremost reflect senior management intent - the people accountable for the organization's direction, risk tolerance, and resource allocation. Without that alignment, policies lack authority, sponsorship, and strategic fit.
Why the distractors fall short:
- A (data security standards): Standards are technical controls that policies may reference, but policies govern the entire security program, not just data - making standards too narrow as a primary driver.
- B (industry best practices): Best practices are useful inputs, but they describe what peers do generically, not what your organization's leadership has decided is appropriate for its specific risk context.
- C (an information security framework): Frameworks (e.g., ISO 27001, NIST CSF) provide structure and guidance, but they are tools that implement policy - not the source of authority that policies should reflect.
Memory tip: Think of policy as the written voice of leadership. Ask yourself, "Who owns the risk?" - that's senior management. Policies translate their intent into enforceable direction. If leadership hasn't sanctioned it, it isn't policy; it's just a suggestion.
Topics
Community Discussion
No community discussion yet for this question.