What type of policy provides instructions on what actions should be avoided by the organization?
Correct Answer: C
A Proscriptive Policy outlines actions or behaviors that should be avoided to ensure compliance, ethical conduct, and risk mitigation.
* Definition of Proscriptive Policies:
* Focus on prohibited activities or practices that may harm the organization or breach regulations.
* Example: Policies banning insider trading or discriminatory practices.
* Purpose:
* Protect the organization from legal, reputational, or operational risks by explicitly identifying unacceptable behaviors.
* Why Other Options Are Incorrect:
* A: Prescriptive policies specify actions that should be taken, not avoided.
* B: Procedural policies provide step-by-step instructions for processes, not prohibitions.
* D: Reactive policies respond to incidents after they occur, rather than proactively avoiding them.
References:
* ISO 37301 (Compliance Management Systems): Discusses proscriptive policies in regulatory compliance.
* COSO Framework: Highlights the role of policies in mitigating risk.