SSCP · Question #1203
A security policy is a rigid set of rules that must be followed explicitly in order to be effective.
The correct answer is B. False. A security policy provides a framework and guidelines for security, but it is not necessarily a rigid set of rules that must be followed explicitly without any room for interpretation or adaptation.
Question
A security policy is a rigid set of rules that must be followed explicitly in order to be effective.
Options
- ATrue
- BFalse
How the community answered
(53 responses)- A13% (7)
- B87% (46)
Why each option
A security policy provides a framework and guidelines for security, but it is not necessarily a rigid set of rules that must be followed explicitly without any room for interpretation or adaptation.
This statement is false because while security policies define critical boundaries and requirements, they often need to be flexible enough to accommodate evolving technologies, business needs, and threat landscapes, rather than being an entirely inflexible set of explicit rules.
Security policies are foundational documents that define an organization's security posture and requirements, but they are not always rigid and allow for interpretation and adaptation to different situations and technologies. While policies set boundaries, procedures and standards provide the explicit, detailed steps.
Concept tested: Characteristics of security policies
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/management#policies-standards-and-guidelines
Topics
Community Discussion
No community discussion yet for this question.