CRISC Certified in Risk and Information Systems Control – Question376

Which of the following is the final step in the policy development process?

A.
Management approval
B. Continued awareness activities
C. Communication to employees
D. Maintenance and review

Correct Answer: D

Explanation:

Explanation:
Organizations should create a structured ISG document development process. A formal process gives many areas the opportunity to comment on a policy. This is very important for high-level policies that apply to the whole organization. A formal process also makes sure that final policies are communicated to employees. It also provides organizations with a way to make sure that policies are reviewed regularly.
In general, a policy development process should include the following steps: 1. Development
2. Stakeholder review
3. Management approval
4. Communication to employees
5. Documentation of compliance or exceptions
6. Continued awareness activities
7. Maintenance and review
Incorrect Answers: A, B, C: These are the earlier phases in policy development process.