GH-100 · Question #5
Our organization is updating its enterprise policies. Which of the following steps should you take to ensure alignment with security requirements?
The correct answer is A. Maintain clear documentation of existing policies and policy changes. B. Implement the new enterprise policies across the organization first and then consult with the. Maintaining clear documentation (A) is essential because it creates accountability, ensures stakeholders understand what changed and why, and provides an audit trail for compliance verification - all foundational to security governance. Option B, though truncated in the…
Question
Our organization is updating its enterprise policies. Which of the following steps should you take to ensure alignment with security requirements?
Options
- AMaintain clear documentation of existing policies and policy changes.
- BImplement the new enterprise policies across the organization first and then consult with the
- CImplement changes without consulting stakeholders.
- DRegularly assess and adjust policies based on evolving risks.
How the community answered
(26 responses)- A81% (21)
- C8% (2)
- D12% (3)
Explanation
Maintaining clear documentation (A) is essential because it creates accountability, ensures stakeholders understand what changed and why, and provides an audit trail for compliance verification - all foundational to security governance. Option B, though truncated in the question, points to a structured rollout process that involves stakeholder consultation, which ensures new policies are understood and applied consistently before gaps can emerge.
Why the distractors are wrong:
- C is incorrect because implementing changes without consulting stakeholders bypasses critical security review, creates resistance, and risks introducing unenforced or misunderstood controls - a major security gap.
- D ("Regularly assess and adjust policies based on evolving risks") is a sound long-term practice, but in the context of an active policy update, it describes ongoing operations rather than the immediate alignment steps required during a rollout, making it a distractor here.
Memory tip: Think of policy updates like a software deployment - you always need documentation (A) to know what changed, and a staged, communicated rollout (B) to ensure adoption. "Document it, then deploy it" keeps you aligned.
Topics
Community Discussion
No community discussion yet for this question.