Courseiva
Security and Risk ManagementeasyMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

Which document is mandatory, high-level, and sets the direction for security within an organization?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Policy

A security policy is a high-level, mandatory document that establishes the overall security direction and principles. Standards, baselines, guidelines, and procedures are more detailed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policy

    Why this is correct

    A policy is a mandatory, high-level statement approved by management, articulating the organization's strategic intent and overarching requirements for information security. It establishes the fundamental rules and direction for protecting assets, often driven by legal, regulatory, or business imperatives, without specifying technical details. Policies are foundational, setting the broad scope and purpose of security efforts across the enterprise.

  • Standard

    Why it's wrong here

    A standard provides specific, mandatory requirements that dictate uniform ways to implement policies across the organization. Unlike high-level policies, standards offer detailed technical specifications or methods, ensuring consistency in security controls and configurations. They translate the broad objectives of a policy into actionable, enforceable mandates for specific technologies or processes, but do not set the initial high-level direction themselves.

  • Procedure

    Why it's wrong here

    A procedure consists of detailed, step-by-step instructions outlining the exact actions to be taken to perform a specific task or process securely. While mandatory for operational consistency, procedures are tactical documents, far more granular than policies, and do not establish the overall strategic direction. They ensure tasks are executed correctly and consistently, supporting standards and policies at an operational level rather than defining the organizational security posture.

  • Baseline

    Why it's wrong here

    A baseline defines the minimum security configurations and settings that must be applied to systems, applications, or network devices to achieve a secure state. These are technical, mandatory starting points for security, ensuring a foundational level of protection, but they do not articulate the high-level organizational security strategy. Baselines are specific technical requirements derived from standards and policies, rather than setting the overarching organizational direction or intent.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.