nerdexam
Isaca

CISM · Question #689

What should be the PRIMARY objective of an information security policy?

The correct answer is A. To outline management expectations. The primary objective of an information security policy is to communicate management’s expectations regarding the protection of information assets, establishing a foundation for governance, accountability, and enforcement.

Submitted by fernanda_arg· Apr 18, 2026Information Security Governance

Question

What should be the PRIMARY objective of an information security policy?

Options

  • ATo outline management expectations
  • BTo ensure alignment with industry best practices
  • CTo detail security procedures
  • DTo comply with regulatory requirements

How the community answered

(41 responses)
  • A
    93% (38)
  • B
    5% (2)
  • C
    2% (1)

Explanation

The primary objective of an information security policy is to communicate management’s expectations regarding the protection of information assets, establishing a foundation for governance, accountability, and enforcement.

Topics

#Information Security Policy#Management Expectations#Security Governance#Policy Objective

Community Discussion

No community discussion yet for this question.

Full CISM Practice