Which of the following statements best describes how a security policy should be written?
A.
It should be direct, concise, and easily readable by those expected to follow it
B.
It should be written in formal, legal language similar to a business contract between two parties
C.
It should be as comprehensive as possible, and cover every possible contingency in as much detail as possible
The Answer Is:
A
This question includes an explanation.
Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
A good security policy must be clear, concise, and easily understandable by its audience (A). This ensures compliance and effective implementation.
Writing in overly formal legal language (B) can create barriers to understanding and practical application.
Overly comprehensive policies (C) risk being ignored due to complexity.
GICSP stresses that policies must balance completeness with clarity to be effective governance tools.
[Reference:, , GICSP Official Study Guide, Domain: ICS Security Governance & Compliance, , NIST SP 800-100 (Information Security Handbook), , GICSP Training on Policy Development and Communication]
GICSP PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 75% Discount on All Products,
Use Coupon: "ac75sure"