nerdexam
EXIN

ISFS · Question #33

You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy. Why is it so…

The correct answer is A. The information security policy gives direction to the information security efforts. An information security policy is the foundational document that sets the organization's direction, goals, and principles for protecting information - without it, all subsequent security activities lack alignment and purpose. Option A is correct because a policy operates at the…

Information security policy

Question

You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy. Why is it so important to have an information security policy as a starting point?

Options

  • AThe information security policy gives direction to the information security efforts.
  • BThe information security policy supplies instructions for the daily practice of information security.
  • CThe information security policy establishes which devices will be protected.
  • DThe information security policy establishes who is responsible for which area of information security.

How the community answered

(29 responses)
  • A
    83% (24)
  • B
    3% (1)
  • C
    10% (3)
  • D
    3% (1)

Explanation

An information security policy is the foundational document that sets the organization's direction, goals, and principles for protecting information - without it, all subsequent security activities lack alignment and purpose. Option A is correct because a policy operates at the strategic level, telling the organization why and what to protect, which everything else flows from.

Why the distractors are wrong:

  • B is wrong because procedures and guidelines supply daily practice instructions - the policy itself is too high-level for day-to-day operational detail.
  • C is wrong because asset registers or scope documents identify which devices/assets are protected, not the policy itself.
  • D is wrong because roles and responsibilities are defined in supporting documents like a security framework or organizational chart, though they may reference the policy.

Memory tip: Think of the policy as the compass, not the map. It points the direction (A), but you need separate tools for the route (B), landmarks (C), and who's driving (D).

Topics

#information security policy#policy direction#strategic planning#security governance

Community Discussion

No community discussion yet for this question.

Full ISFS Practice