Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 Exam ISSEP Topic 5 Question 44 Discussion

Actual exam question for ISC2's Information Systems Security Engineering Professional exam
Question #: 44
Topic #: 5
[All Information Systems Security Engineering Professional Questions]

A security policy is an overall general statement produced by senior management that dictates what

role security plays within the organization. Which of the following are required to be addressed in a

well designed policy? Each correct answer represents a part of the solution. Choose all that apply.

Show Suggested Answer Hide Answer
Suggested Answer: A, B, C

A security policy is an overall general statement produced by senior management (or a selected

policy board or committee) that dictates what

role security plays within the organization.

A well designed policy addresses the following:

What is being secured? - Typically an asset.

Who is expected to comply with the policy? - Typically employees.

Where is the vulnerability, threat, or risk? - Typically an issue of integrity or responsibility.


Contribute your Thoughts:

Currently there are no comments in this discussion, be the first to comment!


Save Cancel