CISM - Information Security Program (33% of the exam) - Section 3.4

Develop and maintain information security policies, procedures and guidelines that govern programme activities.

Develop and maintain a policy hierarchy that includes a security policy, supporting standards, and guidelines, with an acceptable use policy governing personnel behaviour. Distinguish between mandatory policy and standards versus advisory guidelines, and recognise the circumstances that trigger a policy review.

Security policyAcceptable use policyPolicy hierarchyStandards vs guidelines

Practice question for this objective

Free sampleInformation Security Programeasy

While reviewing the security document set, an auditor notes that one document mandates a minimum password length of twelve characters that every system must enforce, while another only recommends that users choose passphrases they find easy to remember. What is the key difference between a standard and a guideline that explains why one is mandatory and the other is not?

  • AA standard sets a mandatory requirement that must be met, while a guideline offers advisory recommendations that are not binding Correct
  • BA standard applies only to technical staff, while a guideline applies to every employee in the organisation
  • CA standard is a temporary measure pending approval, while a guideline is the permanent version once it is ratified
  • DA standard is written by external regulators, while a guideline is written internally by the security team
Distinguish standards as mandatory requirements from guidelines as advisory recommendations within the security document hierarchy. Standards impose mandatory, measurable requirements that enforce a policy, while guidelines provide optional recommended practice, so compliance is required for the former and discretionary for the latter.

Why A is correct: Correct: standards are compulsory and enforceable requirements that support a policy, whereas guidelines are recommended good practice that staff may adapt.

Why B is wrong: Tempting because audiences can differ, but the mandatory or advisory nature of a document is not determined by which audience it targets.

Why C is wrong: Tempting because document lifecycles exist, but standards and guidelines are distinct document types rather than draft and final versions of the same document.

Why D is wrong: Tempting because regulators do issue standards, but internal standards are common, so authorship does not define whether a document is mandatory.

See more CISM practice questions, answers explained.

Exam traps in Information Security Program

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • The standard, which fixes the mandatory technology settings and metrics every relevant system must enforce

    Why it is wrong: Tempting because standards are mandatory and detailed, but they implement policy intent and sit below it, deriving their authority from the policy above.

  • The business continuity plan, which sets out how the organisation recovers operations after a disruption

    Why it is wrong: Tempting because it is a recognised security document, but a business continuity plan addresses recovery after disruption rather than day-to-day rules for using systems.

  • A measurable rise in the volume of help-desk tickets relating to password resets across the workforce

    Why it is wrong: Tempting because operational pain can signal a usability problem, but ticket volume is an operational metric that rarely warrants rewriting governance-level policy rather than adjusting a procedure.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.