Which statement correctly distinguishes an acceptable use policy from a standard operating procedure?
- AAn acceptable use policy lists repair steps, while an SOP sets the network access rules for staff
- BBoth documents exist mainly to track the warranty status of company-owned assets
- CAn acceptable use policy sets the rules for user behaviour, while an SOP defines how to perform a task Correct
- DAn SOP is signed by every user, while an acceptable use policy is read only by auditors
Why A is wrong: This pairs the two document types with real-sounding roles, but it reverses them, since the AUP governs use and the SOP lists the steps.
Why B is wrong: Warranty tracking is genuine IT documentation, which makes this tempting, but that is the role of asset management, not of an AUP or an SOP.
Why C is correct: This correctly separates the two: the AUP governs what users may and may not do, while the SOP prescribes the ordered steps for completing a routine task.
Why D is wrong: Signed acknowledgement sounds like a real control, which makes this plausible, but it is the AUP that users typically sign, and auditors are not its only readers.