HCISPP · Question #274
Which of the following is the BEST reason for writing an information security policy?
The correct answer is A. To support information security governance. An information security policy is the cornerstone of information security governance. It establishes management's intent, assigns roles and responsibilities, sets the direction for all security activities, and provides the framework within which all other security standards…
Question
Which of the following is the BEST reason for writing an information security policy?
Options
- ATo support information security governance
- BTo reduce the number of audit findings
- CTo deter attackers
- DTo implement effective information security controls
How the community answered
(57 responses)- A91% (52)
- B2% (1)
- C5% (3)
- D2% (1)
Explanation
An information security policy is the cornerstone of information security governance. It establishes management's intent, assigns roles and responsibilities, sets the direction for all security activities, and provides the framework within which all other security standards, procedures, and controls are developed. While policies may reduce audit findings (B) or enable controls (D), those are downstream effects - the primary purpose is to support governance.
Topics
Community Discussion
No community discussion yet for this question.