CISM Certified Information Security Manager – Question0574

A PRIMARY purpose of creating security policies is to:

A.
implement management’s governance strategy.
B. establish the way security tasks should be executed.
C. communicate management’s security expectations.
D. define allowable security boundaries.

Correct Answer: B