nerdexam
(ISC)2

SSCP · Question #958

What is the difference between Advisory and Regulatory security policies?

The correct answer is C. Advisory policies are not mandated. Regulatory policies must be implemented.. Regulatory policies are mandated by law, government regulation, or industry standards (e.g., HIPAA, PCI-DSS, SOX) and must be implemented - non-compliance carries legal or financial penalties. Advisory policies are strongly recommended best practices that guide behavior, but they

Submitted by rania.sa· Apr 18, 2026Security Concepts and Practices

Question

What is the difference between Advisory and Regulatory security policies?

Options

  • Athere is no difference between them
  • Bregulatory policies are high level policy, while advisory policies are very detailed
  • CAdvisory policies are not mandated. Regulatory policies must be implemented.
  • DAdvisory policies are mandated while Regulatory policies are not

How the community answered

(59 responses)
  • A
    5% (3)
  • B
    3% (2)
  • C
    90% (53)
  • D
    2% (1)

Explanation

Regulatory policies are mandated by law, government regulation, or industry standards (e.g., HIPAA, PCI-DSS, SOX) and must be implemented - non-compliance carries legal or financial penalties. Advisory policies are strongly recommended best practices that guide behavior, but they are not legally required and compliance is not strictly enforced. Organizations are advised to follow them but are not penalized for non-compliance. Option B reverses the correct relationship between detail levels. Option D incorrectly swaps which type is mandated. Option A is incorrect because there is a meaningful and important distinction between the two types.

Topics

#Security Policies#Regulatory Compliance#Policy Types#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full SSCP Practice