Guide: Security Policies and Procedures
Why it is important:
Security policies and procedures are the foundation of the information security program within an organization. They establish clear guidelines for actions in various situations, define responsibilities, and provide a framework for the implementation of security measures.
What it is:
Security policies are high-level plans that outline the security goals of an organization. Procedures are step-by-step instructions to accomplish a specific task aligned with the security policy. In essence, policies define 'what', while procedures explain 'how'.
How it works:
A security policy outlines the procedure such as how the organization responds to a cybersecurity incident, while the procedure provides detailed steps, for instance, the first action would be to isolate the affected system, next report it to the concerned authority, and so on.
Answering Exam Questions on Security Policies and Procedures:
Be familiar with different types of security policies and their purpose within an organization. Understand that procedures are action-oriented and related to policies. Know how to identify whether a given scenario adheres to a policy/procedure or not.
Exam Tips:
1. Get to the gist of the question quickly - know exactly what is being asked.
2. Examples provided in the question are there to guide you towards the correct answer - analyze them thoroughly.
3. Always opt for the most secure answer when options seem to address the question equally.