nerdexam
(ISC)2

SSCP · Question #1329

Information Security policies should be __________________? (Choose all that apply)

The correct answer is A. Written down B. ClearlyCommunicated to all system users C. Audited and revised periodically. Effective information security policies must be formally documented, clearly communicated to all users, and regularly audited and revised to maintain their relevance and enforceability.

Submitted by akirajp· Apr 18, 2026Security Concepts and Practices

Question

Information Security policies should be __________________? (Choose all that apply)

Options

  • AWritten down
  • BClearlyCommunicated to all system users
  • CAudited and revised periodically
  • DNone of the choices listed are correct

How the community answered

(43 responses)
  • A
    95% (41)
  • D
    5% (2)

Why each option

Effective information security policies must be formally documented, clearly communicated to all users, and regularly audited and revised to maintain their relevance and enforceability.

AWritten downCorrect

Documenting policies ensures clarity, consistency, and provides a traceable record of an organization's security expectations and requirements.

BClearlyCommunicated to all system usersCorrect

Clear communication ensures that all personnel are aware of their security responsibilities and understand the rules they are expected to follow, promoting compliance.

CAudited and revised periodicallyCorrect

Regular auditing and revision are crucial to keep policies current with evolving threats, technologies, business changes, and regulatory requirements, maintaining their effectiveness over time.

DNone of the choices listed are correct

This choice is incorrect because options A, B, and C are all fundamental characteristics of robust information security policies.

Concept tested: Characteristics of effective security policies

Source: https://learn.microsoft.com/en-us/compliance/regulatory/auditing-security-policy

Topics

#Information Security Policies#Policy Management#Policy Communication#Policy Review

Community Discussion

No community discussion yet for this question.

Full SSCP Practice