A CISO is reviewing the organization's information security policies. The organization has recently acquired several smaller companies, each with its own legacy systems and unique operational requirements. The CISO wants to ensure that the current policy framework is flexible enough to accommodate these diverse environments without compromising overall security objectives. Which characteristic of the policy framework is MOST crucial in this scenario?
- AIt should be principles-based, allowing for diverse implementation methods while ensuring adherence to overarching security objectives.
- BIt must be highly prescriptive, detailing exact technical configurations for all systems.
- CIt must be enforced uniformly across all entities without any exceptions or deviations.
- DIt needs to be entirely replaced with the policies of the largest acquired company to ensure standardization.
Show answer & explanationAnswer & explanation
Correct answer: A. It should be principles-based, allowing for diverse implementation methods while ensuring adherence to overarching security objectives.
In a diverse environment like one with recent acquisitions and legacy systems, a highly prescriptive policy is impractical. A principles-based framework provides the necessary flexibility, allowing different entities to implement security controls in a way that suits their unique context, while still meeting the organization's core security objectives. This prevents compromise of overall security objectives.
Why the other options are wrong
- B. Highly prescriptive policies are rigid and often unworkable in diverse, complex environments, leading to non-compliance.
- C. Uniform enforcement without considering diverse operational context can lead to impracticality and security gaps.
- D. Replacing policies with one acquired company's might not be suitable for the entire diverse organization and can lead to resistance.
Principles-Based Policy Framework
An information security policy structure that sets high-level objectives and guiding principles, allowing individual business units or systems flexibility in implementing specific controls to achieve those principles.
- Promotes adaptability in diverse environments.
- Focuses on 'what' to achieve, not strictly 'how'.
- Balances consistency with operational flexibility.
Memory trick: Build a strong foundation, but let each room have its own decor.