Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

BCS CISMP-V9 Exam - Topic 3 Question 118 Discussion

Which of the following is NOT a valid statement to include in an organisation's security policy?
B) The policy has been agreed and amended to suit all third party contractors.
A) The policy has the support of Board and the Chief Executive.
C) How the organisation will manage information assurance.
D) The compliance with legal and regulatory obligations.

BCS CISMP-V9 Exam - Topic 3 Question 118 Discussion

Actual exam question for BCS's CISMP-V9 exam
Question #: 118
Topic #: 3
[All CISMP-V9 Questions]

Which of the following is NOT a valid statement to include in an organisation's security policy?

Show Suggested Answer Hide Answer
Suggested Answer: B

An organization's security policy should be a reflection of its own security stance and principles, not tailored to third parties. While it may be informed by third-party requirements, the policy itself should not be amended to suit all third-party contractors. This is because the security policy is meant to establish a clear set of rules and expectations for the organization's members to maintain the confidentiality, integrity, and availability of its data. It should be defined, approved by management, and communicated to employees and relevant external parties. Amending the policy to suit all third-party contractors could lead to a dilution of the security standards and potentially compromise the organization's security posture.


Contribute your Thoughts:

0/2000 characters
Ona
3 days ago
D is essential for any policy, no doubt!
upvoted 0 times
...
Sheron
8 days ago
Wait, how can B be agreed by all contractors? Sounds off.
upvoted 0 times
...
Jamal
13 days ago
A is super important for buy-in!
upvoted 0 times
...
Elke
19 days ago
I agree, B doesn't make sense.
upvoted 0 times
...
Vanna
24 days ago
B is definitely not valid.
upvoted 0 times
...
Eugene
29 days ago
I have a vague memory that compliance with legal obligations is usually a must in these policies, so D should be valid too.
upvoted 0 times
...
Arlean
1 month ago
I recall a practice question that mentioned the importance of board support in a policy. So, A seems like a solid statement to include.
upvoted 0 times
...
Tien
1 month ago
I'm not entirely sure, but I feel like all the options could be valid statements. Maybe I should have reviewed the specific requirements for security policies more thoroughly.
upvoted 0 times
...
Nidia
1 month ago
I think option B might be the one that's not valid. I remember something about policies needing to be broad, not just tailored for third parties.
upvoted 0 times
...

Save Cancel