SSCP · Question #1149
What is the minimum recommended length of a security policy?
The correct answer is D. There is no minimum length - the policy length should support the business needs. The appropriate length of a security policy is determined by the specific business requirements and scope, rather than a fixed minimum page count.
Question
What is the minimum recommended length of a security policy?
Options
- A200 pages
- B5 pages
- C1 page
- DThere is no minimum length - the policy length should support the business needs
How the community answered
(31 responses)- A3% (1)
- B6% (2)
- D90% (28)
Why each option
The appropriate length of a security policy is determined by the specific business requirements and scope, rather than a fixed minimum page count.
A policy that is excessively long might be difficult to read, understand, and implement, making it less effective.
Five pages might be too short for a comprehensive security policy in many organizations, potentially omitting critical details or scope.
A single page is almost certainly insufficient to cover the complex security requirements of any but the smallest and simplest organizations.
A security policy should be comprehensive enough to address all relevant security aspects of an organization, but its length is highly dependent on the organization's size, complexity, industry, regulatory requirements, and the specific topics it covers. There is no universal minimum length, as the policy's effectiveness is measured by its clarity, completeness, and enforceability, not its page count.
Concept tested: Security policy development principles
Topics
Community Discussion
No community discussion yet for this question.