212k views
2 votes
Which type of document sets overall direction for an information security program? (Actively manage risk, consider compliance and regulatory requirements, layered compensating controls, etc.)

Policy

Process

Strategy

Guideline

1 Answer

1 vote

Answer: Policy

Step-by-step explanation:

The information security policy is the type of the document which sets the overall direction for the information security program. This program is in the form of documentation where it include all the information of the organization about the security policies, guidelines, standard and the procedure.

The main principle of the security program is that it provide the integrity, availability and the confidentiality in terms of the information security. It also helps in protecting the various confidential data.

Therefore, policy is the correct option.

User Rjmunro
by
4.6k points