HCISPP · Question #12
Which one of the following is NOT a fundamental component of a Regulatory Security Policy?
The correct answer is C. Who is to do it. Regulatory Security Policies are compliance-driven mandates that define what must be done, when it must be done, and why it must be done - establishing the legal or organizational obligation. "Who is to do it" (C) belongs to procedural or operational documentation, not the…
Question
Which one of the following is NOT a fundamental component of a Regulatory Security Policy?
Options
- AWhat is to be done.
- BWhen it is to be done.
- CWho is to do it.
- DWhy is it to be done
How the community answered
(29 responses)- A3% (1)
- B7% (2)
- C90% (26)
Explanation
Regulatory Security Policies are compliance-driven mandates that define what must be done, when it must be done, and why it must be done - establishing the legal or organizational obligation. "Who is to do it" (C) belongs to procedural or operational documentation, not the regulatory policy itself; assigning responsibility is handled through roles, procedures, or standards that implement the policy.
Why the distractors are wrong:
- A (What) - Core. The policy must state the required action or control.
- B (When) - Core. Timing and deadlines define compliance windows and enforceability.
- D (Why) - Core. The rationale anchors the policy to a regulation, law, or business need, justifying its existence.
Memory tip: Think of a Regulatory Security Policy as a government law - laws tell you what is prohibited, when it takes effect, and why it exists (public safety, rights, etc.), but they don't name who specifically will enforce or comply. That detail lives in implementing regulations and procedures.
Topics
Community Discussion
No community discussion yet for this question.