nerdexam
(ISC)2

SSCP · Question #957

What is the goal of the Maintenance phase in a common development process of a security policy?

The correct answer is A. to review the document on the specified review date. The security policy lifecycle typically includes phases such as Regulatory Review, Creation/Development, Review/Approval, Publication, and Maintenance. The Maintenance phase occurs after the policy has already been approved and published. Its primary goal is to ensure the…

Submitted by yuki_2020· Apr 18, 2026Security Concepts and Practices

Question

What is the goal of the Maintenance phase in a common development process of a security policy?

Options

  • Ato review the document on the specified review date
  • Bpublication within the organization
  • Cto write a proposal to management that states the objectives of the policy
  • Dto present the document to an approving body

How the community answered

(30 responses)
  • A
    90% (27)
  • B
    7% (2)
  • D
    3% (1)

Explanation

The security policy lifecycle typically includes phases such as Regulatory Review, Creation/Development, Review/Approval, Publication, and Maintenance. The Maintenance phase occurs after the policy has already been approved and published. Its primary goal is to ensure the policy remains current and effective by reviewing it on a scheduled date and updating it as necessary to reflect changes in the business environment, threats, or regulations. The other options describe earlier phases: writing a proposal is part of the initiation phase, presenting to an approving body is the approval phase, and publication is its own distinct phase.

Topics

#Security Policy#Policy Lifecycle#Policy Maintenance#Policy Review

Community Discussion

No community discussion yet for this question.

Full SSCP Practice