Systems Security Certified Practitioner – SSCP – Question0355

What can best be defined as high-level statements, beliefs, goals and objectives?

A.
Standards
B. Policies
C. Guidelines
D. Procedures

Correct Answer: B

Explanation:

Policies are high-level statements, beliefs, goals and objectives and the general means for their attainment for a specific subject area. Standards are mandatory activities, action, rules or regulations designed to provide policies with the support structure and specific direction they require to be effective. Guidelines are more general statements of how to achieve the policies objectives by providing a framework within which to implement procedures. Procedures spell out the specific steps of how the policy and supporting standards and how guidelines will be implemented.
Source: HARE, Chris, Security management Practices CISSP Open Study Guide, version 1.0, april 1999.