ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

A CISA is auditing an organization's approach to information security. The CISA observes that the security policies are largely descriptive, outlining what 'should be done' but lacking specific instructions or measurable outcomes. Which of the following is the MOST significant concern for the CISA regarding these policies?

  1. AThey can be easily misinterpreted by employees due to their general nature.
  2. BThey require frequent updates to remain relevant to technological changes.
  3. CThey make it difficult to enforce compliance and measure effectiveness.
  4. DThey may not adequately address emerging threats and vulnerabilities.
Show answer & explanation

Correct answer: C. They make it difficult to enforce compliance and measure effectiveness.

Descriptive policies that lack specific instructions and measurable outcomes severely hinder the organization's ability to enforce compliance and objectively assess whether the policies are achieving their intended security goals. Without clear metrics and actionable directives, it is challenging to hold individuals accountable or to demonstrate policy effectiveness.

Why the other options are wrong

  • A. Misinterpretation is a consequence, but the inability to enforce and measure is a more fundamental and significant problem for policy governance.
  • B. Policy relevance is a separate issue from the difficulty in enforcing and measuring vague policies.
  • D. While a concern, this is a broader issue of policy maintenance, not the primary concern stemming from policies lacking specific instructions and measurable outcomes.

Actionable Security Policy

An actionable security policy provides clear, specific, and measurable directives that enable effective enforcement and evaluation of compliance and effectiveness.

  • Defines 'what' and 'how' to achieve security objectives.
  • Includes measurable outcomes or indicators of compliance.
  • Facilitates accountability and auditability.

Memory trick: An 'ACT'ive policy ensures Security, Compliance, and Transparency.

More Domain 2: Governance and Management of IT questions