CISM Certified Information Security Manager – Question0023

Which of the following is MOST likely to be discretionary?

A.
Policies
B. Procedures
C. Guidelines
D. Standards

Correct Answer: C

Explanation:

Explanation:
Policies define security goals and expectations for an organization. These are defined in more specific terms within standards and procedures. Standards establish what is to be done while procedures describe how it is to be done. Guidelines provide recommendations that business management must consider in developing practices within their areas of control; as such, they are discretionary.