CISM Certified Information Security Manager – Question0025

Which of the following are seldom changed in response to technological changes?

A.
Standards
B. Procedures
C. Policies
D. Guidelines

Correct Answer: C

Explanation:

Explanation:
Policies are high-level statements of objectives. Because of their high-level nature and statement of broad operating principles, they are less subject to periodic change. Security standards and procedures as well as guidelines must be revised and updated based on the impact of technology changes.