nerdexam
(ISC)2

SSCP · Question #1193

Information security policies are a ___________________.

The correct answer is C. Business enabler. Information security policies are crucial tools that safeguard organizational assets, ensure compliance, and enable business operations by mitigating risks.

Submitted by chen.hong· Apr 18, 2026Security Concepts and Practices

Question

Information security policies are a ___________________.

Options

  • ANecessary evil
  • BWaste of time
  • CBusiness enabler
  • DInconvenience for the end user
  • EAll of the answers are correct

How the community answered

(31 responses)
  • B
    3% (1)
  • C
    90% (28)
  • D
    6% (2)

Why each option

Information security policies are crucial tools that safeguard organizational assets, ensure compliance, and enable business operations by mitigating risks.

ANecessary evil

While policies may impose restrictions, they are fundamentally designed for protection and risk reduction, not as an 'evil' necessity.

BWaste of time

Security policies are essential for governance, risk management, and compliance, making them a critical investment rather than a waste of time.

CBusiness enablerCorrect

Information security policies serve as a business enabler by establishing a secure framework that protects critical data and systems, ensures regulatory compliance, and builds stakeholder trust, thereby facilitating safe and uninterrupted business operations.

DInconvenience for the end user

Though some policies might introduce minor inconveniences for end-users, their overarching benefit of securing the organization far outweighs these small drawbacks.

EAll of the answers are correct

Concept tested: Purpose of security policies

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/information-protection?view=o365-worldwide

Topics

#Information Security Policies#Security Governance#Business Alignment#Risk Management

Community Discussion

No community discussion yet for this question.

Full SSCP Practice