ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementEasy

A multinational corporation is developing a new cloud-based application that will process sensitive customer data across various jurisdictions. To ensure consistent security practices and legal compliance, the Chief Information Security Officer (CISO) mandates the creation of a high-level document that defines the organization's overall security stance and objectives for the application, applicable to all employees and contractors. Which type of document is the CISO mandating?

  1. ASecurity Standard
  2. BSecurity Procedure
  3. CSecurity Policy
  4. DSecurity Guideline
Show answer & explanation

Correct answer: C. Security Policy

A security policy is a high-level statement from senior management that defines the overall security objectives and rules for an organization. It sets the direction for all security efforts and is mandatory.

Why the other options are wrong

  • A. A security standard specifies mandatory requirements for specific technologies or configurations, more granular than an overall stance.
  • B. A security procedure provides detailed, step-by-step instructions for specific tasks, not high-level objectives.
  • D. A security guideline offers recommendations and best practices, which are not mandatory high-level rules.

Security Policy

A high-level document, typically approved by senior management, that defines an organization's overall security objectives, rules, and acceptable practices. It sets the strategic direction for information security.

  • Mandatory and applies to all relevant personnel.
  • High-level and technology-independent.
  • Serves as the foundation for standards, guidelines, and procedures.

Memory trick: Policies are the 'King' – high-level rules for all.

More Security and Risk Management questions