ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium

A new regulation mandates that all customer data collected by an organization must be encrypted both in transit and at rest. The organization updates its security procedures to include specific steps for encrypting data, and IT staff are trained on these new procedures. Which element of the security governance framework is represented by the 'specific steps for encrypting data'?

  1. AGuideline
  2. BProcedure
  3. CStandard
  4. DPolicy
Show answer & explanation

Correct answer: B. Procedure

Procedures are detailed, step-by-step instructions on how to perform a specific task to achieve a desired outcome. The 'specific steps for encrypting data' directly align with this definition.

Why the other options are wrong

  • A. A guideline provides recommendations, which are less prescriptive than specific steps.
  • C. A standard specifies mandatory requirements for hardware or software, but not the 'how-to' steps.
  • D. A policy is a high-level statement of management's intent, not specific steps.

Procedure (Security)

Detailed, step-by-step instructions on how to perform a specific task or set of tasks to achieve a desired security objective.

  • Highly prescriptive and mandatory for compliance.
  • Often derived from policies and standards.
  • Ensures consistency and repeatability of security operations.

Memory trick: Policy is the law, Standard is the rule, Guideline is advice, Procedure is how-to.

More Security Principles questions