ITPEC IP April 2018 Question 45

Source exam: ITPEC IP April 2018Topic: Security

ITPEC IP April 2018 — Question 45 of 100

An organization's top-level information security policy must be unified across the organization, even when departments implement different detailed measures. The common policy expresses management direction, objectives, responsibilities, and principles; lower-level standards and procedures adapt implementation to particular risks and operations.

Answer (d)

Why not others:
- management approves and supports the policy, but detailed operational procedures are implemented by responsible organizational roles

- internal security rules and procedures need not all be published externally

- the top-level policy should reflect the organization's own context rather than be copied unchanged from a model

Key rule: One organization-wide policy provides consistent direction, while standards and procedures translate it into context-specific controls.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.