SSCP · Question #1329
Information Security policies should be __________________? (Choose all that apply)
The correct answer is A. Written down B. ClearlyCommunicated to all system users C. Audited and revised periodically. Effective information security policies must be formally documented, clearly communicated to all users, and regularly audited and revised to maintain their relevance and enforceability.
Question
Information Security policies should be __________________? (Choose all that apply)
Options
- AWritten down
- BClearlyCommunicated to all system users
- CAudited and revised periodically
- DNone of the choices listed are correct
How the community answered
(43 responses)- A95% (41)
- D5% (2)
Why each option
Effective information security policies must be formally documented, clearly communicated to all users, and regularly audited and revised to maintain their relevance and enforceability.
Documenting policies ensures clarity, consistency, and provides a traceable record of an organization's security expectations and requirements.
Clear communication ensures that all personnel are aware of their security responsibilities and understand the rules they are expected to follow, promoting compliance.
Regular auditing and revision are crucial to keep policies current with evolving threats, technologies, business changes, and regulatory requirements, maintaining their effectiveness over time.
This choice is incorrect because options A, B, and C are all fundamental characteristics of robust information security policies.
Concept tested: Characteristics of effective security policies
Source: https://learn.microsoft.com/en-us/compliance/regulatory/auditing-security-policy
Topics
Community Discussion
No community discussion yet for this question.