CRISC · Question #422
Which of the following deficiencies identified during a review of an organization's cybersecurity policy should be of MOST concern?
The correct answer is D. The policy has not been approved by the organization's board. An unapproved cybersecurity policy represents the most critical deficiency because it lacks the necessary organizational authority and commitment to be effectively implemented and enforced.
Question
Which of the following deficiencies identified during a review of an organization's cybersecurity policy should be of MOST concern?
Options
- AThe policy lacks specifics on how to secure the organization's systems from cyberattacks.
- BThe policy has gaps against relevant cybersecurity standards and frameworks.
- CThe policy has not been reviewed by the cybersecurity team in over a year.
- DThe policy has not been approved by the organization's board.
How the community answered
(55 responses)- A5% (3)
- B2% (1)
- C13% (7)
- D80% (44)
Why each option
An unapproved cybersecurity policy represents the most critical deficiency because it lacks the necessary organizational authority and commitment to be effectively implemented and enforced.
While lacking specifics is a flaw, policies generally provide high-level direction, with detailed implementation typically covered by standards and procedures; an unapproved policy cannot enforce any specifics regardless.
Gaps against standards indicate weaknesses in content, but an unapproved policy fundamentally lacks the authority to address those gaps or enforce any remediation efforts.
An outdated policy is problematic, but even a current policy without board approval fundamentally lacks the necessary organizational backing to be truly effective or enforceable.
A cybersecurity policy must be formally approved by the highest levels of management, such as the board, to signify top-down commitment, establish its authority, and ensure it aligns with the organization's strategic objectives and risk appetite. Without board approval, the policy lacks the organizational mandate required for effective implementation and enforcement across the entire enterprise.
Concept tested: Cybersecurity policy governance and approval
Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-governance-strategy-risk-management#gv-2-define-and-implement-security-policies-and-standards
Topics
Community Discussion
No community discussion yet for this question.