CISM Certified Information Security Manager – Question1138

Requiring all employees and contractors to meet personnel security/suitability requirements commensurate with their position sensitivity level and subject to personnel screening is an example of a security:

A.
policy.
B. strategy.
C. guideline
D. baseline.

Correct Answer: A

Explanation:

Explanation:
A security policy is a general statement to define management objectives with respect to security. The security strategy addresses higher level issues. Guidelines are optional actions and operational tasks. A security baseline is a set of minimum requirements that is acceptable to an organization.