ITPEC IP October 2023 Question 36
ITPEC IP October 2023 — Question 36 of 100
An organization's top-level information security policy should be unified across the organization even when detailed measures differ by department. The policy states common management direction, objectives, principles, scope, and responsibilities. Department-specific rules and procedures then implement it according to differing risks and operations.
Answer (d)
Why not others:
- (a) management approves and supports the policy, but detailed operational procedures are normally implemented by responsible organizational functions
- (b) internal rules and procedures may contain sensitive details and need not be published externally
- (c) the top-level policy must reflect the organization's own objectives and risks, not be copied unchanged from an industry model
Key rule: One organization-wide policy provides direction; subordinate standards and procedures tailor implementation.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.