QuestionQ215

Security Concepts and Practices

Which of the following characteristics should an effective information security policy not have?

  • A Include separation of duties
  • B Be designed with a short- to mid-term focus
  • C Be understandable and supported by all stakeholders
  • D Specify areas of responsibility and authority
Explanation

An information security policy should provide stable, long-term management direction. Short- and mid-term objectives or implementation details are better addressed through supporting standards, procedures, and plans. Policies should instead clearly assign responsibility and authority and be understandable to, and supported by, relevant stakeholders.

Community Discussion

No comments yet. Be the first to start the discussion!