ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium
An organization is updating its information security policy. The draft policy includes a statement: 'All sensitive data must be encrypted in transit.' However, it does not specify the encryption algorithms, key lengths, or protocols to be used. What is the MOST significant shortcoming of this policy statement from an audit perspective?
- AIt does not assign responsibility for implementing the encryption.
- BIt lacks clarity regarding the types of sensitive data covered.
- CIt is not sufficiently actionable or enforceable due to lack of specificity.
- DIt fails to address encryption for data at rest, only data in transit.
Show answer & explanationAnswer & explanation
Correct answer: C. It is not sufficiently actionable or enforceable due to lack of specificity.
From an audit perspective, a policy statement must be clear, measurable, and enforceable. Without specifying 'how' encryption should be achieved (algorithms, key lengths, protocols), the policy becomes difficult to implement consistently and impossible to audit for compliance effectively, making it not actionable or enforceable.
Why the other options are wrong
- A. Responsibility assignment is crucial for implementation, but the policy's primary role is to state 'what' should be done and provide enough detail for 'how' it should be done to be consistently implementable.
- B. While important, 'sensitive data' can often be defined in supporting standards or procedures. The lack of 'how' is more critical for enforceability.
- D. A policy can focus on specific areas. The omission of 'data at rest' is a scope limitation, not a critical shortcoming of the statement itself, which focuses on 'in transit'.
Actionable Security Policy
An information security policy that is specific, measurable, achievable, relevant, and time-bound (SMART), providing clear directives for implementation and allowing for effective auditing.
- Must define 'what' and 'how'.
- Enables consistent compliance.
- Facilitates audit and enforcement.
Memory trick: A good policy is clear, firm, and verifiable.