nerdexam
EXIN

ISFS · Question #54

What is the goal of an organization's security policy?

The correct answer is A. To provide direction and support to information security. Option A is correct because a security policy operates at the strategic/management level - its purpose is to establish organizational intent, assign responsibilities, and provide the overarching direction that guides all information security efforts. It answers why and what at…

Information security policy

Question

What is the goal of an organization's security policy?

Options

  • ATo provide direction and support to information security
  • BTo define all threats to and measures for ensuring information security
  • CTo document all incidents that threaten the reliability of information
  • DTo document all procedures required to maintain information security

How the community answered

(28 responses)
  • A
    79% (22)
  • B
    7% (2)
  • C
    11% (3)
  • D
    4% (1)

Explanation

Option A is correct because a security policy operates at the strategic/management level - its purpose is to establish organizational intent, assign responsibilities, and provide the overarching direction that guides all information security efforts. It answers why and what at a high level, not how.

  • B is wrong because no policy can exhaustively define all threats; threat landscapes evolve constantly, and that detail belongs in risk assessments and threat models, not policy.
  • C is wrong because documenting incidents is the job of an incident log or incident response record, not a security policy.
  • D is wrong because documenting procedures is the role of standards, guidelines, and work instructions - documents that sit below policy in the hierarchy.

Memory tip: Think of the acronym PDSG (Policy → Direction, Standards → Specifics, Guidelines → Guidance, Procedures → Steps). A policy always sits at the top giving direction - everything else fills in the details beneath it.

Topics

#security policy#management direction#information security support

Community Discussion

No community discussion yet for this question.

Full ISFS Practice