nerdexam
Isaca

CISM · Question #942

The security baselines of an organization should be based on:

The correct answer is C. standards. Standards define the specific, mandatory requirements that security baselines must meet - they are measurable, enforceable, and technology-specific (e.g., "all passwords must be 12+ characters"), making them the natural foundation for baselines. Policies (A) are too high-level…

Submitted by sofia.br· Apr 18, 2026Information Security Governance

Question

The security baselines of an organization should be based on:

Options

  • Apolicies.
  • Bguidelines.
  • Cstandards.
  • Dprocedures.

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    85% (22)
  • D
    4% (1)

Explanation

Standards define the specific, mandatory requirements that security baselines must meet - they are measurable, enforceable, and technology-specific (e.g., "all passwords must be 12+ characters"), making them the natural foundation for baselines.

Policies (A) are too high-level - they state what must be done ("data must be protected") but not how, so they can't anchor a technical baseline. Guidelines (B) are advisory and optional, meaning they carry no enforcement weight and can't reliably define a minimum security posture. Procedures (D) describe step-by-step how to implement something, which comes after a baseline is established, not before.

Memory tip: Think of the hierarchy - Policies → Standards → Baselines → Procedures. Baselines are a concrete expression of standards, so they must be based on standards. The word "baseline" itself implies a measurable minimum, which only standards (not optional guidelines) can provide.

Topics

#Security baselines#Information security standards#Information security policies#Information security governance framework

Community Discussion

No community discussion yet for this question.

Full CISM Practice