Certified Information Security Manager (CISM)Information Security GovernanceMedium

An organization is updating its information security policy framework. To ensure the framework remains adaptable to future technological changes and evolving business needs, which characteristic is MOST important for its design?

  1. AAnnual comprehensive review and revision cycle for all policy documents.
  2. BStrict adherence to a single, internationally recognized security standard (e.g., ISO 27002).
  3. CEmphasis on principles-based policies with separate, adaptable implementation guidelines.
  4. DIncorporation of highly detailed, technology-specific configurations and procedures.
Show answer & explanation

Correct answer: C. Emphasis on principles-based policies with separate, adaptable implementation guidelines.

An emphasis on principles-based policies with separate, adaptable implementation guidelines is most important. This allows the core policy framework to remain stable (principles) while the detailed 'how-to' (guidelines) can be updated more frequently to reflect technological changes without rewriting the entire policy.

Why the other options are wrong

  • A. An annual review is a process for maintenance, but the design characteristic itself should enable flexibility to make that review more efficient and effective.
  • B. While using a standard is good, strict adherence without flexibility can hinder adaptability to unique organizational or technological needs.
  • D. Highly detailed, technology-specific policies become quickly outdated and are difficult to maintain in a dynamic environment.

Flexible Policy Framework

An information security policy structure designed to remain relevant and effective despite changes in technology, business processes, and regulatory landscapes, often achieved through a layered, principles-based approach.

  • Separates high-level principles from low-level details.
  • Allows for agile adaptation of implementation.
  • Reduces overhead for policy updates.

Memory trick: Keep the core rules steady, but let the how-to's dance with tech's flow.

More Information Security Governance questions