nerdexam
Isaca

CISM · Question #324

Which of the following is the MOST important objective of an IT acceptable use policy?

The correct answer is B. To document expectations for utilizing organizational resources. An Acceptable Use Policy (AUP) exists primarily to define and communicate what is and isn't permitted when using organizational resources (systems, networks, devices, data) - making B the core purpose by definition. Why the distractors are wrong: A is incorrect because managing…

Submitted by mike_84· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is the MOST important objective of an IT acceptable use policy?

Options

  • ATo manage third-party access to organizational resources
  • BTo document expectations for utilizing organizational resources
  • CTo align business units to the information security policy
  • DTo demonstrate employee acknowledgement of information security policies

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    94% (32)
  • D
    3% (1)

Explanation

An Acceptable Use Policy (AUP) exists primarily to define and communicate what is and isn't permitted when using organizational resources (systems, networks, devices, data) - making B the core purpose by definition.

Why the distractors are wrong:

  • A is incorrect because managing third-party access is the purpose of a third-party access policy or vendor management controls, not an AUP, which targets internal users.
  • C is incorrect because aligning business units to the information security policy is the role of the information security policy itself (or governance frameworks), not the AUP.
  • D is incorrect because employee acknowledgement (signatures, sign-offs) is a process step in enforcing an AUP - it's a mechanism, not the policy's objective.

Memory tip: Think of AUP = "Allowed Use Playbook." Its job is to set expectations before anyone touches a resource. Everything else (third-party controls, acknowledgements, alignment) is either a different policy or a downstream activity that flows from having those documented expectations.

Topics

#Acceptable Use Policy#Policy Objectives#Information Security Policy#User Expectations

Community Discussion

No community discussion yet for this question.

Full CISM Practice