CISA Protection of Information Assets Practice Question
During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?
⚠ Common exam trap
CISA often tests the policy vs. procedure vs. standard distinction; candidates pick 'define roles and responsibilities' because it sounds governance-oriented, but that is a supporting artifact, not the policy's primary purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To communicate management's commitment and direction for information security
The primary purpose of an information security policy is to communicate management's commitment, intent, and direction for information security across the organization. It is a high-level governance document that establishes the mandate from which standards, procedures, and guidelines flow. It is not intended to be technically prescriptive or operational.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To provide detailed step-by-step instructions for implementing security controls
Why it's wrong here
Step-by-step implementation instructions belong in procedures, which translate policy into operational tasks. The policy itself states management intent and direction at a high level. It is tempting because policies, standards and procedures are frequently bundled in one document set, but embedding procedural detail undermines the policy's stability and approval scope.
- ✗
To specify the technical configurations for security devices
Why it's wrong here
Technical configuration belongs in standards, baselines and hardening guides, which sit below policy in the hierarchy. An information security policy states management's intent, objectives and principles. It is tempting because policies and standards are often stored together, yet configuration detail is deliberately excluded from policy to keep it stable and technology-neutral.
- ✗
To define the roles and responsibilities for information security
Why it's wrong here
Assigning roles and responsibilities is a supporting element, not the primary purpose; the policy's core is stating management's intent, objectives and principles for protecting information. It is tempting because responsibility statements commonly appear inside policy documents, yet they flow from the policy's direction rather than defining its purpose.
- ✓
To communicate management's commitment and direction for information security
Why this is correct
The policy exists to articulate management's commitment and strategic direction for information security, authorising the programme and setting expectations. This satisfies the stem's constraint by establishing the mandate from which standards, procedures and controls derive their authority.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.