ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITEasy
An organization is developing an information security policy. Which of the following is the MOST critical initial step in this process?
- ASelecting security technologies to enforce the policy.
- BDefining the scope and objectives of the policy.
- CConducting a comprehensive risk assessment.
- DTraining employees on security awareness.
Show answer & explanationAnswer & explanation
Correct answer: C. Conducting a comprehensive risk assessment.
A comprehensive risk assessment is the most critical initial step because it identifies the organization's specific information assets, threats, vulnerabilities, and the potential impact of security incidents. This understanding forms the foundation for developing relevant and effective security policies that address actual risks.
Why the other options are wrong
- A. Technology selection comes after understanding what needs to be protected and from what, which is informed by risk assessment and policy.
- B. Defining scope and objectives is important, but these should be informed by the understanding of risks, making risk assessment a precursor.
- D. Employee training is crucial for policy implementation, but it's not the initial step in *developing* the policy itself.
Information Security Policy Development
The structured process of creating formal documents that outline an organization's stance on information security, defining rules, responsibilities, and expected behaviors.
- Driven by risk assessment.
- Requires management approval.
- Communicated to all stakeholders.
Memory trick: Build your security policy house on a solid risk assessment foundation.