Which policy provides high-level direction for an organization's information security program?

Study for the EC-Council Network Defense Essentials Test. Utilize flashcards and multiple-choice questions, with each question accompanied by hints and explanations. Prepare effectively for your examination!

Multiple Choice

Which policy provides high-level direction for an organization's information security program?

Explanation:
The policy that provides high-level direction for an organization’s information security program is the Enterprise Information Security Policy. It sets the overall direction, including the security objectives, the scope of the program, roles and responsibilities, management support, and how risk is approached. This top-level policy guides and constrains all other security activities and policies, ensuring they align with business goals. An Issue Specific Security Policy focuses on a single topic or area, not the entire program. Procedural Security Requirements describe how to perform security tasks, and Safeguard Security Requirements specify particular controls, both of which are more detailed and specific than the broad direction established by the EISP.

The policy that provides high-level direction for an organization’s information security program is the Enterprise Information Security Policy. It sets the overall direction, including the security objectives, the scope of the program, roles and responsibilities, management support, and how risk is approached. This top-level policy guides and constrains all other security activities and policies, ensuring they align with business goals. An Issue Specific Security Policy focuses on a single topic or area, not the entire program. Procedural Security Requirements describe how to perform security tasks, and Safeguard Security Requirements specify particular controls, both of which are more detailed and specific than the broad direction established by the EISP.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy