ISFS · Question #67
Why do organizations have an information security policy?
The correct answer is C. In order to give direction to how information security is set up within an organization. An information security policy exists to give direction and purpose to how an organization manages and protects its information assets - setting the overall tone, goals, and framework from which all other security controls and procedures flow. Without this guiding document…
Question
Why do organizations have an information security policy?
Options
- AIn order to demonstrate the operation of the Plan-Do-Check-Act cycle within an organization.
- BIn order to ensure that staff do not break any laws.
- CIn order to give direction to how information security is set up within an organization.
- DIn order to ensure that everyone knows who is responsible for carrying out the backup procedures.
How the community answered
(49 responses)- A4% (2)
- B2% (1)
- C92% (45)
- D2% (1)
Explanation
An information security policy exists to give direction and purpose to how an organization manages and protects its information assets - setting the overall tone, goals, and framework from which all other security controls and procedures flow. Without this guiding document, security efforts would be inconsistent and lack strategic alignment.
Why the distractors are wrong:
- A is incorrect because the Plan-Do-Check-Act (PDCA) cycle is a management process for continuous improvement - it may be used alongside a policy, but it's not the reason the policy exists.
- B is too narrow; legal compliance is one outcome of good security, but policies also address risks and organizational needs that go far beyond just avoiding legal violations.
- D describes a specific procedure (backup responsibilities), which would live in an operational document, not the high-level policy itself.
Memory tip: Think of the information security policy as the organization's security "North Star" - it points everyone in the right direction. Specific rules, responsibilities, and processes (like backups or legal compliance) are stars that follow from it, not the other way around.
Topics
Community Discussion
No community discussion yet for this question.