hardMultiple Choice
CISA Practice Question: An IT auditor is reviewing the organization's…
An IT auditor is reviewing the organization's policy hierarchy. Which of the following correctly represents the typical order from highest to lowest level?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy, Standard, Guideline, Procedure, Work instruction
The hierarchy is: Policy (high-level principles), Standard (mandatory requirements), Guideline (recommended practices), Procedure (step-by-step instructions), Work instruction (detailed task-level instructions).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy, Guideline, Standard, Procedure, Work instruction
Why it's wrong here
Guidelines are discretionary recommendations that sit below standards, so placing Guideline second misorders the chain. It is tempting because guidelines are advisory and often confused with standards, but this order would be correct only if guidelines were mandatory and standards optional.
- ✓
Policy, Standard, Guideline, Procedure, Work instruction
Why this is correct
Policy sits at the top, stating management intent, followed by standards that mandate specific controls, then guidelines, procedures and work instructions. Each lower layer becomes progressively more detailed and operational, satisfying the hierarchy the auditor must verify.
- ✗
Procedure, Policy, Standard, Guideline, Work instruction
Why it's wrong here
Procedures are operational, step-level documents that sit near the bottom of the hierarchy, so leading with Procedure inverts the authority chain. It is tempting because procedures are mandatory, but they would rank highest only in a scenario where no policy or standard existed above them.
- ✗
Standard, Policy, Guideline, Procedure, Work instruction
Why it's wrong here
This reverses the hierarchy: standards sit below policies, and guidelines sit below standards, so placing Standard first inverts the authority chain. It is tempting because all five artefacts exist, but the ordering is correct only when policy is named as the highest-level document.
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.