CISSP - Security and Risk Management - Section 1.6

Develop, document, and implement security policy, standards, procedures, and guidelines.

Describe the hierarchy of security policy documents - policies, standards, baselines, procedures, and guidelines - and explain the purpose and authority level of each. Apply this hierarchy to determine which document type should govern a specific control or operational requirement.

security policystandardsbaselinesproceduresguidelines

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A risk committee is debating whether two new documents should be drafted as standards or as guidelines. The first will require all internet-facing web services to enforce a named transport encryption configuration; the second will suggest preferred ways for staff to label sensitive files on shared drives. Which classification best reflects accepted security-document practice?

  • ADraft both documents as standards, so that legal and audit teams have clear evidence of mandatory enforcement.
  • BDraft the transport encryption document as a standard and the file-labelling document as a guideline, matching mandatory and advisory intent. Correct
  • CDraft both documents as guidelines, because operational staff need flexibility to adapt controls to their own work patterns.
  • DDraft the transport encryption document as a procedure and the file-labelling document as a baseline configuration.
Recognise that standards are mandatory while guidelines are advisory, and apply each label to documents according to enforcement intent. The standard and guideline distinction is essentially about enforceability. Standards bind the organisation to a specific implementation choice and produce auditable evidence of compliance, whereas guidelines acknowledge that good outcomes can be reached by different paths and leave discretion with the practitioner. Aligning document type with enforcement intent preserves the meaning of each tier.

Why A is wrong: Making advisory file-labelling content a standard would impose obligatory rules where flexibility is desired and would dilute the meaning of 'standard' across the document set.

Why B is correct: Standards are mandatory and prescriptive, suitable for an enforceable encryption configuration, while guidelines are advisory and well suited to recommended, judgement-based practices such as labelling sensitive files.

Why C is wrong: Internet-facing encryption is a control the organisation must be able to enforce and audit; treating it as advisory would weaken assurance and breach common regulatory expectations.

Why D is wrong: A procedure describes step-by-step actions and a baseline defines a minimum configuration; neither captures the mandatory-versus-advisory distinction the committee actually has to choose between.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security and Risk Management objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.