CISSP Security and Risk Management Practice Question
Which of the following is a key difference between a policy and a guideline in information security governance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policies are mandatory, while guidelines are recommended
Policies are high-level, mandatory statements that define the organization's security posture. Guidelines are recommendations that suggest best practices but are not mandatory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policies are created by IT, while guidelines are created by executives
Why it's wrong here
This statement is incorrect because the creation of policies and guidelines is not strictly segregated by department. While IT personnel often contribute significantly to the development of security policies, especially technical ones, policies typically require formal approval from senior management or executives to ensure organizational authority, widespread enforcement, and alignment with business objectives. Guidelines can also originate from various departments, including executive leadership, to provide recommended best practices without the mandatory compliance aspect of a policy.
- ✗
Policies are technical, while guidelines are managerial
Why it's wrong here
This option is inaccurate as the scope of both policies and guidelines can span technical and managerial domains. Policies can be high-level, strategic directives (managerial), such as an "Acceptable Use Policy," or very specific, technical requirements, like a "Password Complexity Policy" detailing specific algorithms or lengths. Similarly, guidelines can offer managerial advice on risk assessment or detailed technical instructions for secure system configuration. The nature of their content does not serve as a distinguishing factor between them.
- ✓
Policies are mandatory, while guidelines are recommended
Why this is correct
This is the correct distinction. Policies are formal, high-level statements that mandate specific actions or behaviors, establishing compulsory rules that all relevant parties must adhere to, with non-compliance typically incurring disciplinary or legal consequences. In contrast, guidelines provide recommended best practices, suggestions, or advisory information designed to assist individuals in making informed decisions or performing tasks, but they are not strictly enforced. This fundamental difference in obligation and enforceability is key to their purpose within an organization's governance framework.
- ✗
Policies are static, while guidelines are updated frequently
Why it's wrong here
This statement is incorrect because neither policies nor guidelines are inherently static or frequently updated relative to each other. Both types of documents are dynamic and must be regularly reviewed and revised to reflect changes in the threat landscape, technology, regulatory requirements, or organizational structure. While policies might aim for a degree of stability due to their mandatory nature and the effort involved in formal approval, they are certainly not immune to necessary updates, and guidelines are not exclusively characterized by more frequent revisions; both respond to evolving needs.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Security posture
An organization's overall cybersecurity strength, including policies, controls, and readiness to defend against and respond to threats.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.