A company wants one document that tells employees what they are required to do when handling company systems and data. Which document type is the best fit?
Trap 1: Procedure, because it always defines the highest-level mandatory…
A procedure is a defined sequence of actions or tasks used to complete a specific process, such as a step-by-step incident response checklist. It is not a high-level rule set; it derives its authority from policies and describes 'how' rather than 'what' employees must always do. Procedures are also rarely company-wide in scope and are typically tailored to a workflow or system, so they cannot be the single document that defines mandatory rules for everyone.
Trap 2: Guideline, because it provides optional suggestions for best…
Although guidelines do provide recommended best practices, they are by definition discretionary and use language like 'should' or 'may,' leaving room for employee judgment. The company's stated need is for a single document that tells employees what they are required to do; an optional framework would not establish enforceable expectations or support compliance audits. Thus a guideline fails because it cannot convey binding, organization-wide mandates.
Trap 3: Standard, because it contains only optional advice about security.
Standards are actually mandatory, not optional advice; they define specific implementation details such as encryption requirements, password complexity rules, or platform baseline settings. However, a standard is usually subordinate to a policy and applies to particular technologies or processes rather than serving as the overarching, company-wide rule document. The option's claim that a standard contains 'only optional advice' is factually incorrect, which makes it a poor justification even if the conclusion might seem plausible.
- A
Policy, because it states the required rules and expectations for everyone.
A policy is the top-level document that states mandatory rules and expectations. It is appropriate when the organization wants all employees to know the required behavior for handling systems and data. Policies are broad, approved by leadership, and intended to guide consistent decisions across the company.
- B
Procedure, because it always defines the highest-level mandatory rules.
Why wrong: A procedure is a defined sequence of actions or tasks used to complete a specific process, such as a step-by-step incident response checklist. It is not a high-level rule set; it derives its authority from policies and describes 'how' rather than 'what' employees must always do. Procedures are also rarely company-wide in scope and are typically tailored to a workflow or system, so they cannot be the single document that defines mandatory rules for everyone.
- C
Guideline, because it provides optional suggestions for best behavior.
Why wrong: Although guidelines do provide recommended best practices, they are by definition discretionary and use language like 'should' or 'may,' leaving room for employee judgment. The company's stated need is for a single document that tells employees what they are required to do; an optional framework would not establish enforceable expectations or support compliance audits. Thus a guideline fails because it cannot convey binding, organization-wide mandates.
- D
Standard, because it contains only optional advice about security.
Why wrong: Standards are actually mandatory, not optional advice; they define specific implementation details such as encryption requirements, password complexity rules, or platform baseline settings. However, a standard is usually subordinate to a policy and applies to particular technologies or processes rather than serving as the overarching, company-wide rule document. The option's claim that a standard contains 'only optional advice' is factually incorrect, which makes it a poor justification even if the conclusion might seem plausible.