easyMultiple SelectObjective-mapped
CISSP Practice Question: Which TWO are essential components of a security…
Which TWO are essential components of a security policy framework?
⚠ Common exam trap
Many exam-takers confuse operational documents (flowcharts, diagrams, key lengths) with the foundational governance components of a policy framework, which must always include scope and accountability to be enforceable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Roles and responsibilities
Roles and responsibilities (D) are essential because they define who is accountable for implementing, maintaining, and enforcing the security policy. Without clear assignment of duties, policy execution becomes unenforceable and audit trails lack ownership, violating the separation of duties principle central to the Security and Risk Management domain.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Specific encryption key lengths
Why it's wrong here
Specific encryption key lengths are technical implementation details that belong in security standards or guidelines, not within the high-level security policy framework itself. A policy sets the overarching requirement for strong encryption to protect sensitive data, but specifying granular technical parameters like 'AES-256' or 'RSA 2048-bit' would make the policy overly prescriptive, difficult to maintain, and prone to rapid obsolescence as technology evolves. Policies focus on 'what' must be achieved, leaving 'how' to supporting documentation.
- ✗
Incident response flowcharts
Why it's wrong here
Incident response flowcharts are detailed, step-by-step instructions that form part of security procedures, not the foundational policy document. While a security policy mandates the establishment of an incident response capability and defines high-level objectives, the specific visual representations and sequential actions for handling incidents are operational procedures. Policies define the organizational commitment and requirements for incident management, whereas flowcharts provide the actionable, granular steps for personnel to follow during an event.
- ✗
Network topology diagrams
Why it's wrong here
Network topology diagrams are operational or architectural documentation, providing a visual representation of the network's physical or logical layout. These diagrams are essential for network design, management, and troubleshooting, and they support the implementation of security controls. However, they are not intrinsic components of the security policy framework itself, which focuses on establishing rules, directives, and responsibilities rather than depicting infrastructure configurations.
- ✓
Roles and responsibilities
Why this is correct
Defining roles and responsibilities is an essential component of a security policy framework because it assigns accountability and clarifies who is responsible for specific security tasks and decisions. This ensures that all personnel understand their obligations regarding information security, from data ownership and system administration to compliance monitoring. Without clearly delineated roles, policies lack enforceability and the organization cannot effectively manage its security posture, leading to potential gaps and failures in implementation.
- ✓
Statement of scope
Why this is correct
A clear statement of scope is fundamental to a security policy framework as it precisely defines what the policy applies to, including specific assets, systems, data, personnel, and organizational boundaries. This clarity prevents ambiguity and ensures that the policy's directives are consistently applied across the intended environment. Without a well-defined scope, the policy's applicability could be misinterpreted, leading to inconsistent security practices or critical areas being inadvertently excluded from coverage.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Separation of duties
Separation of duties is a security principle that splits critical tasks and privileges among multiple people to prevent fraud, errors, and abuse of power.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.