Secure Software Lifecycle Professional – CSSLP – Question317

Which of the following statements describe the main purposes of a Regulatory policy? Each correct answer represents a complete solution. Choose all that apply.

A.
It acknowledges the importance of the computing resources to the business model
B. It provides a statement of support for information security throughout the enterprise
C. It ensures that an organization is following the standard procedures or base practices of operation in its specific industry.
D. It gives an organization the confidence that it is following the standard and accepted industry policy.

Correct Answer: CD

Explanation:

Explanation: The main purposes of a Regulatory policy are as follows: It ensures that an organization is following the standard procedures or base practices of operation in its specific industry. It gives an organization the confidence that it is following the standard and accepted industry policy. Answer: B and A are incorrect. These are the policy elements of Senior Management Statement of Policy.