CompTIA Security+ (SY0-701)Security Program Management and OversightEasy
A newly hired CISO wants to create a high-level document that states management's overall intent and direction for the security program. The document will be approved by executive leadership and reviewed annually, but it will not contain specific technical instructions. Which document type should be created?
- APolicy
- BGuideline
- CStandard
- DProcedure
Show answer & explanationAnswer & explanation
Correct answer: A. Policy
A policy is a high-level statement of management intent and direction, approved by leadership, that sets the framework for the security program. Standards, procedures, and guidelines are more detailed documents that support policy implementation.
Why the other options are wrong
- B. Guidelines are recommended, non-mandatory best practices.
- C. Standards define specific, mandatory technical requirements, not high-level intent.
- D. Procedures are step-by-step instructions for performing tasks.
Governance Document Hierarchy
Policies set high-level intent, standards define mandatory requirements, procedures give step-by-step instructions, and guidelines offer recommendations.
- Policies are approved by executive leadership
- Standards support policies with specific requirements
- Procedures are the most detailed, task-level documents
Memory trick: Policies Say What, Standards Set Specs, Procedures Push Steps, Guidelines Give Suggestions