Systems Security Certified Practitioner – SSCP – Question0340

What is the goal of the Maintenance phase in a common development process of a security policy?

A.
to review the document on the specified review date
B. publication within the organization
C. to write a proposal to management that states the objectives of the policy
D. to present the document to an approving body

Correct Answer: A

Explanation:

“publication within the organization” is the goal of the Publication Phase “write a proposal to management that states the objectives of the policy” is part of Initial and Evaluation Phase “Present the document to an approving body” is part of Approval Phase.
Reference: TIPTON, Harold F. & KRAUSE, MICKI, Information Security Management Handbook, 4th Edition, Volume 3, 2002, Auerbach Publications. Also: KRUTZ, Ronald L. & VINES, Russel D., The CISSP Prep Guide: Mastering the Ten Domains of Computer Security, John Wiley & Sons, 2001, Chapter 8: Business Continuity Planning and Disaster Recovery Planning (page 286).