CRISC Certified in Risk and Information Systems ControlGovernanceMedium

A retail company is planning to launch a new mobile payment application that will handle sensitive customer financial data. The board is concerned about the potential for data breaches and the associated reputational damage. To mitigate this risk, the board asks for a clear articulation of the organization's stance on data protection and privacy. Which of the following documents would BEST provide this high-level strategic direction?

  1. AA comprehensive incident response plan.
  2. BTechnical specifications for the mobile application's security features.
  3. CThe organization's information security policy.
  4. DA detailed data encryption standard for the mobile application.
Show answer & explanation

Correct answer: C. The organization's information security policy.

An information security policy provides the high-level strategic direction and overarching principles for data protection and privacy. It outlines the organization's commitment, objectives, and responsibilities, which is what the board would require to understand the company's stance.

Why the other options are wrong

  • A. An incident response plan is operational, detailing how to react to breaches, not the strategic stance on prevention.
  • B. Technical specifications are granular implementation details, not the overarching policy or strategic direction.
  • D. Data encryption standards are technical implementation details, not high-level strategic direction.

Policies, Standards, and Procedures

Hierarchical documents that define an organization's objectives, mandatory requirements, and detailed steps for achieving them, respectively.

  • Policies state 'what' should be done.
  • Standards state 'how' to meet policies.
  • Procedures detail 'who, what, when, where, why' for specific tasks.

Memory trick: Policy is the strategic 'what', guiding data's path.

More Governance questions