CISM - Information Security Program - Section 3.4

Develop and maintain information security policies, procedures and guidelines that govern programme activities.

Develop and maintain a policy hierarchy that includes a security policy, supporting standards, and guidelines, with an acceptable use policy governing personnel behaviour. Distinguish between mandatory policy and standards versus advisory guidelines, and recognise the circumstances that trigger a policy review.

Security policyAcceptable use policyPolicy hierarchyStandards vs guidelines

Practice question for this objective

Free sampleInformation Security Programeasy

While reviewing the security document set, an auditor notes that one document mandates a minimum password length of twelve characters that every system must enforce, while another only recommends that users choose passphrases they find easy to remember. What is the key difference between a standard and a guideline that explains why one is mandatory and the other is not?

  • AA standard sets a mandatory requirement that must be met, while a guideline offers advisory recommendations that are not binding Correct
  • BA standard applies only to technical staff, while a guideline applies to every employee in the organisation
  • CA standard is a temporary measure pending approval, while a guideline is the permanent version once it is ratified
  • DA standard is written by external regulators, while a guideline is written internally by the security team
Distinguish standards as mandatory requirements from guidelines as advisory recommendations within the security document hierarchy. Standards impose mandatory, measurable requirements that enforce a policy, while guidelines provide optional recommended practice, so compliance is required for the former and discretionary for the latter.

Why A is correct: Correct: standards are compulsory and enforceable requirements that support a policy, whereas guidelines are recommended good practice that staff may adapt.

Why B is wrong: Tempting because audiences can differ, but the mandatory or advisory nature of a document is not determined by which audience it targets.

Why C is wrong: Tempting because document lifecycles exist, but standards and guidelines are distinct document types rather than draft and final versions of the same document.

Why D is wrong: Tempting because regulators do issue standards, but internal standards are common, so authorship does not define whether a document is mandatory.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Program objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.