Courseiva
Security and Risk ManagementmediumMultiple ChoiceObjective-mapped

CISSP Security and Risk Management Practice Question

Which of the following is a key difference between a policy and a guideline in information security governance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Policies are mandatory, while guidelines are recommended

Policies are high-level, mandatory statements that define the organization's security posture. Guidelines are recommendations that suggest best practices but are not mandatory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Policies are created by IT, while guidelines are created by executives

    Why it's wrong here

    This statement is incorrect because the creation of policies and guidelines is not strictly segregated by department. While IT personnel often contribute significantly to the development of security policies, especially technical ones, policies typically require formal approval from senior management or executives to ensure organizational authority, widespread enforcement, and alignment with business objectives. Guidelines can also originate from various departments, including executive leadership, to provide recommended best practices without the mandatory compliance aspect of a policy.

  • Policies are technical, while guidelines are managerial

    Why it's wrong here

    This option is inaccurate as the scope of both policies and guidelines can span technical and managerial domains. Policies can be high-level, strategic directives (managerial), such as an "Acceptable Use Policy," or very specific, technical requirements, like a "Password Complexity Policy" detailing specific algorithms or lengths. Similarly, guidelines can offer managerial advice on risk assessment or detailed technical instructions for secure system configuration. The nature of their content does not serve as a distinguishing factor between them.

  • Policies are mandatory, while guidelines are recommended

    Why this is correct

    This is the correct distinction. Policies are formal, high-level statements that mandate specific actions or behaviors, establishing compulsory rules that all relevant parties must adhere to, with non-compliance typically incurring disciplinary or legal consequences. In contrast, guidelines provide recommended best practices, suggestions, or advisory information designed to assist individuals in making informed decisions or performing tasks, but they are not strictly enforced. This fundamental difference in obligation and enforceability is key to their purpose within an organization's governance framework.

  • Policies are static, while guidelines are updated frequently

    Why it's wrong here

    This statement is incorrect because neither policies nor guidelines are inherently static or frequently updated relative to each other. Both types of documents are dynamic and must be regularly reviewed and revised to reflect changes in the threat landscape, technology, regulatory requirements, or organizational structure. While policies might aim for a degree of stability due to their mandatory nature and the effort involved in formal approval, they are certainly not immune to necessary updates, and guidelines are not exclusively characterized by more frequent revisions; both respond to evolving needs.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.