ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

A CISA is reviewing an organization's information security policy. The policy states that 'all data must be protected' but provides no further details on classification, responsibilities, or specific controls. What is the MOST significant deficiency in this policy statement?

  1. ALack of metrics for measuring policy compliance.
  2. BAbsence of clear, actionable guidance for employees.
  3. CInsufficient detail on incident response procedures.
  4. DFailure to address regulatory compliance requirements.
Show answer & explanation

Correct answer: B. Absence of clear, actionable guidance for employees.

A policy stating 'all data must be protected' without further detail is too vague to be effectively implemented. It fails to provide clear, actionable guidance on *how* data should be protected, by *whom*, and to what *degree*, making it difficult for employees to understand and comply with their security responsibilities.

Why the other options are wrong

  • A. While metrics are important for monitoring, the fundamental issue is the policy's inability to guide action in the first place.
  • C. Incident response is a separate, though related, component; the policy itself needs to define what 'protected' means before IR procedures are developed.
  • D. Regulatory requirements might necessitate more detail, but the immediate and most significant deficiency is the lack of clarity for internal stakeholders.

Actionable Security Policy

An information security policy that is clear, specific, and provides practical guidance to employees on how to fulfill their security responsibilities, rather than just stating high-level principles.

  • Defines roles and responsibilities.
  • Specifies controls and procedures.
  • Is easily understood by its audience.

Memory trick: A good policy is a clear 'how-to' guide, not just a 'should-do' wish.

More Domain 2: Governance and Management of IT questions