Question 1
A global financial institution is implementing a new security framework. The Chief Information Security Officer (CISO) emphasizes that while technical defenses are crucial, the organization must ensure that all employees understand their responsibilities and the consequences of non-compliance. Which governance document should be primarily established to provide this high-level authority and direction?
Answer and explanation
Correct answer: C
A security policy is a high-level document that outlines the organization's security goals, responsibilities, and enforcement. It provides the necessary authority and strategic direction. Standards are mandatory specific rules, and procedures are step-by-step instructions, both of which support the policy but do not provide the high-level authority themselves.