SY0-301 · Question #455
Which of the following provides the BEST explanation regarding why an organization needs to implement IT security policies?
The correct answer is C. To reduce the organizational risk. The primary and overarching purpose of IT security policies is to reduce organizational risk by defining acceptable behavior, establishing controls, and ensuring assets are protected. Option B (staff conforming to policy) is a means to an end, not the reason policies exist…
Question
Which of the following provides the BEST explanation regarding why an organization needs to implement IT security policies?
Options
- ATo ensure that false positives are identified
- BTo ensure that staff conform to the policy
- CTo reduce the organizational risk
- DTo require acceptable usage of IT systems
How the community answered
(36 responses)- A3% (1)
- B3% (1)
- C94% (34)
Explanation
The primary and overarching purpose of IT security policies is to reduce organizational risk by defining acceptable behavior, establishing controls, and ensuring assets are protected. Option B (staff conforming to policy) is a means to an end, not the reason policies exist. Option D (acceptable usage) describes one type of policy, not the holistic purpose. Option A (false positives) relates to detection tools, not policy rationale. Reducing risk encompasses all the other benefits-compliance, access control, acceptable use-making C the best answer.
Topics
Community Discussion
No community discussion yet for this question.