nerdexam
Isaca

CISM · Question #32

An organization has acquired a new system with strict maintenance instructions and schedules. Where should this information be documented?

The correct answer is B. Procedures. Maintenance instructions and schedules, which detail the step-by-step actions required, are best documented as procedures.

Submitted by fatima_kr· Apr 18, 2026Information Security Governance

Question

An organization has acquired a new system with strict maintenance instructions and schedules. Where should this information be documented?

Options

  • AStandards
  • BProcedures
  • CGuidelines
  • DPolicies

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    88% (38)
  • C
    2% (1)
  • D
    2% (1)

Why each option

Maintenance instructions and schedules, which detail the step-by-step actions required, are best documented as procedures.

AStandards

Standards specify mandatory requirements or criteria that must be met, but not the step-by-step method to achieve them.

BProceduresCorrect

Procedures are detailed, step-by-step instructions that describe how to perform a specific task or process, making them the appropriate place for documenting strict maintenance instructions and schedules. They ensure consistency and compliance with operational requirements.

CGuidelines

Guidelines offer recommendations and best practices but are less rigid than strict instructions or procedures.

DPolicies

Policies are high-level statements of management's intent and expectations, not detailed operational steps.

Concept tested: Documentation types for operational tasks

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-12.pdf

Topics

#Documentation types#Operational procedures#System maintenance#Information security framework

Community Discussion

No community discussion yet for this question.

Full CISM Practice