CISSP - Security and Risk Management (16% of the exam) - Section 1.6

Develop, document, and implement security policy, standards, procedures, and guidelines.

Describe the hierarchy of security policy documents - policies, standards, baselines, procedures, and guidelines - and explain the purpose and authority level of each. Apply this hierarchy to determine which document type should govern a specific control or operational requirement.

security policystandardsbaselinesproceduresguidelines

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A risk committee is debating whether two new documents should be drafted as standards or as guidelines. The first will require all internet-facing web services to enforce a named transport encryption configuration; the second will suggest preferred ways for staff to label sensitive files on shared drives. Which classification best reflects accepted security-document practice?

  • ADraft both documents as standards, so that legal and audit teams have clear evidence of mandatory enforcement.
  • BDraft the transport encryption document as a standard and the file-labelling document as a guideline, matching mandatory and advisory intent. Correct
  • CDraft both documents as guidelines, because operational staff need flexibility to adapt controls to their own work patterns.
  • DDraft the transport encryption document as a procedure and the file-labelling document as a baseline configuration.
Recognise that standards are mandatory while guidelines are advisory, and apply each label to documents according to enforcement intent. The standard and guideline distinction is essentially about enforceability. Standards bind the organisation to a specific implementation choice and produce auditable evidence of compliance, whereas guidelines acknowledge that good outcomes can be reached by different paths and leave discretion with the practitioner. Aligning document type with enforcement intent preserves the meaning of each tier.

Why A is wrong: Making advisory file-labelling content a standard would impose obligatory rules where flexibility is desired and would dilute the meaning of 'standard' across the document set.

Why B is correct: Standards are mandatory and prescriptive, suitable for an enforceable encryption configuration, while guidelines are advisory and well suited to recommended, judgement-based practices such as labelling sensitive files.

Why C is wrong: Internet-facing encryption is a control the organisation must be able to enforce and audit; treating it as advisory would weaken assurance and breach common regulatory expectations.

Why D is wrong: A procedure describes step-by-step actions and a baseline defines a minimum configuration; neither captures the mandatory-versus-advisory distinction the committee actually has to choose between.

See more CISSP practice questions, answers explained.

Exam traps in Security and Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • A security standard that mandates specific cryptographic algorithms and minimum key lengths across all systems.

    Why it is wrong: Standards translate policy into mandatory, technology-specific requirements; they do not articulate management intent or carry board approval as their primary function.

  • Reissue the current policy with the outdated references corrected and circulate it again for staff acknowledgement.

    Why it is wrong: Correcting the text addresses the present symptom but not the cause; without a recurring review obligation the same drift will reappear at the next organisational change.

  • Immediately revoke all of her access on the day notice is given, on the basis that any departing employee is an insider threat.

    Why it is wrong: Blanket revocation on the notice date prevents her from completing the work the business has retained her to do, and treats every resignation as hostile. The correct posture is risk-based and proportionate, not reflexive lockout, unless there are specific indicators of risk.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.