nerdexam
Isaca

CRISC · Question #422

Which of the following deficiencies identified during a review of an organization's cybersecurity policy should be of MOST concern?

The correct answer is D. The policy has not been approved by the organization's board. An unapproved cybersecurity policy represents the most critical deficiency because it lacks the necessary organizational authority and commitment to be effectively implemented and enforced.

Submitted by ahmad_uae· Apr 18, 2026Governance

Question

Which of the following deficiencies identified during a review of an organization's cybersecurity policy should be of MOST concern?

Options

  • AThe policy lacks specifics on how to secure the organization's systems from cyberattacks.
  • BThe policy has gaps against relevant cybersecurity standards and frameworks.
  • CThe policy has not been reviewed by the cybersecurity team in over a year.
  • DThe policy has not been approved by the organization's board.

How the community answered

(55 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    13% (7)
  • D
    80% (44)

Why each option

An unapproved cybersecurity policy represents the most critical deficiency because it lacks the necessary organizational authority and commitment to be effectively implemented and enforced.

AThe policy lacks specifics on how to secure the organization's systems from cyberattacks.

While lacking specifics is a flaw, policies generally provide high-level direction, with detailed implementation typically covered by standards and procedures; an unapproved policy cannot enforce any specifics regardless.

BThe policy has gaps against relevant cybersecurity standards and frameworks.

Gaps against standards indicate weaknesses in content, but an unapproved policy fundamentally lacks the authority to address those gaps or enforce any remediation efforts.

CThe policy has not been reviewed by the cybersecurity team in over a year.

An outdated policy is problematic, but even a current policy without board approval fundamentally lacks the necessary organizational backing to be truly effective or enforceable.

DThe policy has not been approved by the organization's board.Correct

A cybersecurity policy must be formally approved by the highest levels of management, such as the board, to signify top-down commitment, establish its authority, and ensure it aligns with the organization's strategic objectives and risk appetite. Without board approval, the policy lacks the organizational mandate required for effective implementation and enforcement across the entire enterprise.

Concept tested: Cybersecurity policy governance and approval

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-governance-strategy-risk-management#gv-2-define-and-implement-security-policies-and-standards

Topics

#Cybersecurity Policy#Board Oversight#Governance Structure#Policy Approval

Community Discussion

No community discussion yet for this question.

Full CRISC Practice