CRISC - Governance - Section 1.4

Evaluate policies and standards as the instruments that translate governance intent into operational control.

Describe the policy hierarchy - from high-level policy through standards to procedures - and how each layer translates governance intent into operational control. Distinguish when an exception process is appropriate and what oversight it requires.

PolicyStandardsExceptionsPolicy hierarchy

Practice question for this objective

Free sampleGovernancemedium

An enterprise policy states that access to confidential data must be restricted to authorised users. A risk practitioner reviewing the control library notes that no document specifies the minimum password length, lockout threshold, or multi-factor requirement that systems must enforce. Which instrument is missing from the policy hierarchy?

  • AA procedure describing the step-by-step tasks an administrator follows to reset a forgotten user password on request.
  • BA guideline suggesting good practices that teams may consider when configuring access for confidential information stores.
  • CA baseline configuration template applied only to a single legacy database server hosting confidential records.
  • DA standard defining the mandatory minimum control parameters that systems must meet to satisfy the access policy. Correct
Standards translate high-level policy intent into mandatory, measurable control requirements that systems must satisfy. Policies state intent and direction, while standards convert that intent into specific mandatory requirements that can be measured and enforced. Without a standard, the access policy has no testable parameters, so the hierarchy is incomplete at the standard layer.

Why A is wrong: A procedure documents how a task is performed, but it does not set the mandatory measurable requirements that systems must meet, so the gap remains.

Why B is wrong: A guideline is advisory and optional, so it cannot define the enforceable thresholds the policy intent depends on; this is a tempting but wrong fit.

Why C is wrong: A device baseline configures one platform rather than setting the enterprise-wide mandatory parameters the policy requires; it is too narrow to close the gap.

Why D is correct: A standard translates broad policy intent into specific, mandatory, measurable requirements such as password length and lockout thresholds, which is exactly the missing layer.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Governance objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.