Courseiva
easyMultiple Choice

CISSP Is developing an information security policy Practice Question

An organization is developing an information security policy. Which of the following should be included?

⚠ Common exam trap

ISC2 often tests the distinction between policy (high-level strategic) and procedure/standard (low-level tactical), so the trap here is confusing incident response playbooks or technical controls as policy elements when they belong in subordinate documents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Roles and responsibilities

An information security policy is a high-level document that establishes management direction and sets the strategic framework for security. Roles and responsibilities must be included to define who is accountable and responsible for security tasks, ensuring clear ownership and governance. This aligns with ISO/IEC 27001 and the NIST SP 800-53 framework, which mandate that policies specify organizational roles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Incident response playbooks

    Why it's wrong here

    Playbooks operationalise the policy's response requirements; they are procedures invoked during incidents, not policy content. A policy states intent, scope and responsibilities. Playbooks belong in supporting standards or runbooks, and would be the right artefact when documenting step-by-step containment actions for specific incident types.

  • ✗

    Detailed technical controls

    Why it's wrong here

    Detailed technical controls specify implementation settings, which belong in standards, baselines or procedures derived from policy. A policy states management intent and mandatory requirements at a conceptual level. Technical controls would be the correct artefact when documenting specific configuration values for platforms, such as cipher suites or timeout thresholds.

  • ✓

    Roles and responsibilities

    Why this is correct

    Policy must assign accountability, so specifying roles and responsibilities ensures each control has a named owner. This satisfies the stem's requirement for content defining who does what, distinguishing it from procedural or technical detail that belongs in supporting standards.

  • ✗

    Vendor contracts

    Why it's wrong here

    Vendor contracts are external legal instruments that flow from policy obligations; they are not policy clauses themselves. A policy defines internal requirements, then contracts encode them. Contracts would be the correct artefact when translating agreed security requirements into enforceable supplier terms with penalties and audit rights.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.