CGRC Policy Development 2 — Questions and Answers
Question 1: Which document type sits at the TOP of a typical policy hierarchy?
- Standard
- Procedure
- Policy (Correct answer)
- Guideline
Correct answer: Policy
Policies are the highest-level documents that establish organizational intent and direction, with standards, procedures, and guidelines sitting below them.
Question 2: A policy exception process PRIMARILY serves to:
- Eliminate the need for the underlying policy
- Document and manage approved deviations from policy requirements (Correct answer)
- Permanently waive compliance obligations for a business unit
- Transfer policy ownership to another department
Correct answer: Document and manage approved deviations from policy requirements
Exception processes provide a formal mechanism to document, approve, and track temporary or permanent deviations while maintaining accountability.
Question 3: When reviewing existing policies for relevance, which trigger MOST warrants an immediate unscheduled review?
- A new employee joins the compliance team
- A significant regulatory change affecting the policy's scope (Correct answer)
- The policy document format becomes outdated
- The policy owner changes roles
Correct answer: A significant regulatory change affecting the policy's scope
Regulatory changes that affect a policy's subject matter require immediate review to ensure ongoing compliance and avoid legal exposure.
Question 4: What is the purpose of including a 'scope' section in a policy document?
- To list the policy's references and citations
- To define which people, systems, or processes the policy applies to (Correct answer)
- To describe penalties for non-compliance
- To outline the policy development methodology used
Correct answer: To define which people, systems, or processes the policy applies to
The scope section clarifies applicability boundaries, specifying which entities, locations, or activities must comply with the policy.
Question 5: A policy that is too prescriptive (overly detailed) creates which PRIMARY risk?
- It becomes easier to audit against
- It may quickly become outdated as processes change (Correct answer)
- It reduces the need for supporting procedures
- It increases employee awareness
Correct answer: It may quickly become outdated as processes change
Overly prescriptive policies embed operational details that change frequently, requiring constant updates and risking non-compliance when procedures evolve.
Question 6: Which party is TYPICALLY responsible for formally approving an enterprise-wide security policy?
- The IT helpdesk manager
- Front-line employees
- Senior leadership or the board of directors (Correct answer)
- External auditors
Correct answer: Senior leadership or the board of directors
Enterprise-wide policies require executive or board-level approval to grant them organizational authority and demonstrate tone at the top.
Question 7: A 'sunset clause' in a policy document refers to:
- A provision that the policy is reviewed annually
- An automatic expiration date after which the policy must be reviewed or renewed (Correct answer)
- A section describing policy communication to employees
- A list of superseded older policy versions
Correct answer: An automatic expiration date after which the policy must be reviewed or renewed
Sunset clauses build in automatic expiration dates to ensure policies do not remain in force indefinitely without periodic review.
Which document type sits at the TOP of a typical policy hierarchy?