nerdexam
(ISC)2

SSCP · Question #1149

What is the minimum recommended length of a security policy?

The correct answer is D. There is no minimum length - the policy length should support the business needs. The appropriate length of a security policy is determined by the specific business requirements and scope, rather than a fixed minimum page count.

Submitted by jaden.t· Apr 18, 2026Security Concepts and Practices

Question

What is the minimum recommended length of a security policy?

Options

  • A200 pages
  • B5 pages
  • C1 page
  • DThere is no minimum length - the policy length should support the business needs

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    6% (2)
  • D
    90% (28)

Why each option

The appropriate length of a security policy is determined by the specific business requirements and scope, rather than a fixed minimum page count.

A200 pages

A policy that is excessively long might be difficult to read, understand, and implement, making it less effective.

B5 pages

Five pages might be too short for a comprehensive security policy in many organizations, potentially omitting critical details or scope.

C1 page

A single page is almost certainly insufficient to cover the complex security requirements of any but the smallest and simplest organizations.

DThere is no minimum length - the policy length should support the business needsCorrect

A security policy should be comprehensive enough to address all relevant security aspects of an organization, but its length is highly dependent on the organization's size, complexity, industry, regulatory requirements, and the specific topics it covers. There is no universal minimum length, as the policy's effectiveness is measured by its clarity, completeness, and enforceability, not its page count.

Concept tested: Security policy development principles

Topics

#Security Policies#Policy Management#Security Governance#Business Needs

Community Discussion

No community discussion yet for this question.

Full SSCP Practice