Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

BCS CISMP-V9 Exam - Topic 3 Question 118 Discussion

Which of the following is NOT a valid statement to include in an organisation's security policy?
B) The policy has been agreed and amended to suit all third party contractors.
A) The policy has the support of Board and the Chief Executive.
C) How the organisation will manage information assurance.
D) The compliance with legal and regulatory obligations.

BCS CISMP-V9 Exam - Topic 3 Question 118 Discussion

Actual exam question for BCS's CISMP-V9 exam
Question #: 118
Topic #: 3
[All CISMP-V9 Questions]

Which of the following is NOT a valid statement to include in an organisation's security policy?

Show Suggested Answer Hide Answer
Suggested Answer: B

An organization's security policy should be a reflection of its own security stance and principles, not tailored to third parties. While it may be informed by third-party requirements, the policy itself should not be amended to suit all third-party contractors. This is because the security policy is meant to establish a clear set of rules and expectations for the organization's members to maintain the confidentiality, integrity, and availability of its data. It should be defined, approved by management, and communicated to employees and relevant external parties. Amending the policy to suit all third-party contractors could lead to a dilution of the security standards and potentially compromise the organization's security posture.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel