nerdexam
(ISC)2

HCISPP · Question #274

Which of the following is the BEST reason for writing an information security policy?

The correct answer is A. To support information security governance. An information security policy is the cornerstone of information security governance. It establishes management's intent, assigns roles and responsibilities, sets the direction for all security activities, and provides the framework within which all other security standards…

Information Governance in Healthcare

Question

Which of the following is the BEST reason for writing an information security policy?

Options

  • ATo support information security governance
  • BTo reduce the number of audit findings
  • CTo deter attackers
  • DTo implement effective information security controls

How the community answered

(57 responses)
  • A
    91% (52)
  • B
    2% (1)
  • C
    5% (3)
  • D
    2% (1)

Explanation

An information security policy is the cornerstone of information security governance. It establishes management's intent, assigns roles and responsibilities, sets the direction for all security activities, and provides the framework within which all other security standards, procedures, and controls are developed. While policies may reduce audit findings (B) or enable controls (D), those are downstream effects - the primary purpose is to support governance.

Topics

#Information Security Policy#Information Security Governance#Security Program Foundation#Policy Development

Community Discussion

No community discussion yet for this question.

Full HCISPP Practice