ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

An organization's information security policy states, 'All employees shall protect company information assets.' However, the policy does not define what constitutes 'company information assets,' nor does it specify protection measures or consequences for non-compliance. What is the MOST significant implication of this policy's wording for information security governance?

  1. AThe organization may be viewed as having a weak security posture by external auditors.
  2. BTraining programs for information security will be difficult to develop.
  3. CThe policy is legally unenforceable in its current form.
  4. DEmployees may inadvertently expose sensitive information due to a lack of clear guidance.
Show answer & explanation

Correct answer: D. Employees may inadvertently expose sensitive information due to a lack of clear guidance.

An effective information security policy must be clear, specific, and actionable. Vague wording that fails to define key terms or specify expected behaviors and consequences makes it impossible for employees to understand or comply with their obligations, leading to inconsistent application and potential security breaches.

Why the other options are wrong

  • A. While true, the direct operational risk of unclear policy leading to employee errors is more significant from a governance enforcement perspective.
  • B. Difficulty in training is a symptom, but the core issue is the policy's inability to guide employee behavior effectively.
  • C. Legal enforceability is a concern, but the immediate and most pervasive risk is the practical failure of the policy to achieve its security objectives.

Actionable Security Policy

An actionable security policy is clearly written, defines key terms, specifies required behaviors, outlines responsibilities, and details consequences for non-compliance, enabling effective implementation and enforcement.

  • Provides clear guidance to employees.
  • Defines scope, responsibilities, and expectations.
  • Essential for consistent security practices.

Memory trick: A blurry map leads to getting lost, not to the treasure of security.

More Domain 2: Governance and Management of IT questions