ISFS · Question #54
What is the goal of an organization's security policy?
The correct answer is A. To provide direction and support to information security. Option A is correct because a security policy operates at the strategic/management level - its purpose is to establish organizational intent, assign responsibilities, and provide the overarching direction that guides all information security efforts. It answers why and what at…
Question
What is the goal of an organization's security policy?
Options
- ATo provide direction and support to information security
- BTo define all threats to and measures for ensuring information security
- CTo document all incidents that threaten the reliability of information
- DTo document all procedures required to maintain information security
How the community answered
(28 responses)- A79% (22)
- B7% (2)
- C11% (3)
- D4% (1)
Explanation
Option A is correct because a security policy operates at the strategic/management level - its purpose is to establish organizational intent, assign responsibilities, and provide the overarching direction that guides all information security efforts. It answers why and what at a high level, not how.
- B is wrong because no policy can exhaustively define all threats; threat landscapes evolve constantly, and that detail belongs in risk assessments and threat models, not policy.
- C is wrong because documenting incidents is the job of an incident log or incident response record, not a security policy.
- D is wrong because documenting procedures is the role of standards, guidelines, and work instructions - documents that sit below policy in the hierarchy.
Memory tip: Think of the acronym PDSG (Policy → Direction, Standards → Specifics, Guidelines → Guidance, Procedures → Steps). A policy always sits at the top giving direction - everything else fills in the details beneath it.
Topics
Community Discussion
No community discussion yet for this question.