An information security manager is structuring the organisation's governance documents. Senior management wants a single document that states, at a high level, management's intent and direction for protecting information assets, while leaving the specific rules and technical settings to lower-level documents. Which type of document should the security manager produce to capture this management intent?
- AA procedure that lists the ordered steps an administrator follows to configure each security control
- BA security policy that expresses management's intent and overall direction for protecting information assets Correct
- CA standard that fixes the mandatory technical settings every system must meet
- DA guideline that offers recommended good practice for staff to consider
Why A is wrong: Tempting because procedures are formal governance documents, but a procedure gives step-by-step instructions for a task, not the high-level statement of management intent the scenario asks for.
Why B is correct: Correct: a policy is the highest-level governance document and exists precisely to state management's intent and direction at a high level, with the detail left to standards and procedures.
Why C is wrong: Tempting because standards are mandatory and authoritative, but a standard specifies detailed mandatory requirements that support a policy rather than expressing the overarching management intent.
Why D is wrong: Tempting because guidelines are part of the document hierarchy, but guidelines are advisory recommendations, so they cannot carry management's binding statement of intent and direction.