Valid CISSP Dumps shared by EduDump.com for Helping Passing CISSP Exam! EduDump.com now offer the newest CISSP exam dumps, the EduDump.com CISSP exam questions have been updated and answers have been corrected get the newest EduDump.com CISSP dumps with Test Engine here:
What is the MOST appropriate hierarchy of documents when implementing a security program?
Correct Answer: A
The most appropriate hierarchy of documents when implementing a security program is organization principle, policy, standard, and guideline. An organization principle is a high-level statement that reflects the values, vision, and mission of the organization and provides the foundation for the security program. A policy is a formal document that defines the goals, objectives, and scope of the security program and assigns roles and responsibilities for its implementation and enforcement. A standard is a specific document that prescribes the mandatory rules, requirements, and procedures for achieving compliance with the policy. A guideline is a flexible document that provides recommendations, best practices, and tips for implementing the standards or addressing specific situations or issues. References: CISSP CBK Reference, 5th Edition, Chapter 1, page 12; CISSP All-in-One Exam Guide, 8th Edition, Chapter 1, page 6