nerdexam
Isaca

CRISC · Question #24

Which of the blowing is MOST important when implementing an organization s security policy?

The correct answer is A. Obtaining management support. Obtaining strong management support is paramount for the successful implementation of an organization's security policy, as it provides the necessary authority, resources, and enforcement power. Without management backing, a policy often lacks credibility and widespread adoption.

Submitted by certguy· Apr 18, 2026Governance

Question

Which of the blowing is MOST important when implementing an organization s security policy?

Options

  • AObtaining management support
  • BBenchmarking against industry standards
  • CAssessing compliance requirements
  • DIdentifying threats and vulnerabilities

How the community answered

(46 responses)
  • A
    78% (36)
  • B
    2% (1)
  • C
    7% (3)
  • D
    13% (6)

Why each option

Obtaining strong management support is paramount for the successful implementation of an organization's security policy, as it provides the necessary authority, resources, and enforcement power. Without management backing, a policy often lacks credibility and widespread adoption.

AObtaining management supportCorrect

Management support provides the authority, resources (budget, personnel), and organizational influence necessary to ensure that the security policy is taken seriously, communicated effectively, and enforced across all levels of the organization. Without it, policies often become ignored or ineffective due to lack of resources or buy-in.

BBenchmarking against industry standards

Benchmarking against industry standards is useful for *developing* a policy and ensuring its comprehensiveness, but it's not the *most important* factor for its successful *implementation*.

CAssessing compliance requirements

Assessing compliance requirements is a critical input for *defining* the policy's content and ensuring legal adherence, but management support is still needed to *implement* the policy that addresses those requirements.

DIdentifying threats and vulnerabilities

Identifying threats and vulnerabilities is essential for determining the *scope and content* of the security policy, but gaining management buy-in is crucial for its actual *execution and enforcement*.

Concept tested: Security policy implementation success factors

Source: https://learn.microsoft.com/en-us/compliance/regulatory/information-security-policy

Topics

#Security Policy#Management Support#Policy Implementation#Organizational Governance

Community Discussion

No community discussion yet for this question.

Full CRISC Practice