nerdexam
EXIN

ISFS · Question #75

What is the greatest risk for an organization if no information security policy has been defined?

The correct answer is D. It is not possible for an organization to implement information security in a consistent manner. Without a defined information security policy, an organization lacks the foundational framework that governs how security measures are selected, applied, and enforced - making consistent implementation impossible across departments, teams, and systems (D). Why the distractors…

Information security policy

Question

What is the greatest risk for an organization if no information security policy has been defined?

Options

  • AIf everyone works with the same account, it is impossible to find out who worked on what.
  • BInformation security activities are carried out by only a few people.
  • CToo many measures are implemented.
  • DIt is not possible for an organization to implement information security in a consistent manner.

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    89% (31)

Explanation

Without a defined information security policy, an organization lacks the foundational framework that governs how security measures are selected, applied, and enforced - making consistent implementation impossible across departments, teams, and systems (D).

Why the distractors are wrong:

  • A describes an access control / accountability problem (solved by unique user accounts), not the absence of a policy itself.
  • B suggests under-staffing or siloed responsibility, which is a management/resource issue, not a direct consequence of having no policy.
  • C is the opposite of reality - without a policy, there is no systematic basis for implementing any measures, let alone too many.

Memory tip: Think of a policy as a "rulebook." Without a rulebook, every team plays by their own rules - no consistency, no shared standard. That's exactly what D describes: the inability to implement security in a consistent manner organization-wide.

Topics

#security policy#consistency#information security management

Community Discussion

No community discussion yet for this question.

Full ISFS Practice