CGRC Policy Development 4 — Questions and Answers
Question 1: Which approach BEST supports consistent policy language across a large organization?
- Allowing each department to write policies independently
- Using a centralized policy template and style guide (Correct answer)
- Publishing policies only in legal department format
- Restricting policy authorship to the CISO only
Correct answer: Using a centralized policy template and style guide
A centralized template and style guide standardizes structure, terminology, and format, ensuring consistency and reducing confusion across the policy library.
Question 2: The 'policy owner' role is PRIMARILY responsible for:
- Drafting all subordinate procedures and work instructions
- Maintaining the policy, ensuring it remains current and enforced (Correct answer)
- Conducting annual employee training on the policy
- Approving budget allocations for compliance activities
Correct answer: Maintaining the policy, ensuring it remains current and enforced
The policy owner is accountable for keeping the policy accurate, relevant, and enforced within their area of responsibility.
Question 3: When developing a data classification policy, which factor MOST influences how many classification tiers to define?
- The number of employees in the organization
- The types of data processed and their sensitivity levels (Correct answer)
- The storage capacity of the organization's servers
- The number of third-party vendors used
Correct answer: The types of data processed and their sensitivity levels
Classification tiers should reflect the actual sensitivity spectrum of the organization's data assets, ensuring controls are proportionate to risk.
Question 4: A policy gap analysis MOST commonly identifies:
- Employees who have not completed policy training
- Areas where no policy exists to address a known risk or requirement (Correct answer)
- Outdated procedures that need reformatting
- Vendors that have not signed data processing agreements
Correct answer: Areas where no policy exists to address a known risk or requirement
A gap analysis compares current policy coverage against required risks or regulations to identify areas lacking adequate policy controls.
Question 5: In policy development, 'plain language' principles are used to:
- Reduce legal liability by avoiding specific commitments
- Make policies understandable to the target audience (Correct answer)
- Satisfy regulatory readability requirements only
- Limit the number of pages in a policy document
Correct answer: Make policies understandable to the target audience
Plain language ensures policies are clear and comprehensible to employees at all levels, increasing the likelihood of understanding and compliance.
Question 6: Which type of policy MOST directly addresses how the organization manages third-party risk?
- Acceptable use policy
- Vendor management or third-party risk policy (Correct answer)
- Incident response policy
- Physical security policy
Correct answer: Vendor management or third-party risk policy
A vendor management or third-party risk policy establishes requirements for assessing, contracting with, and monitoring external parties.
Question 7: When a new policy conflicts with a previously existing policy, the APPROPRIATE resolution is to:
- Allow both policies to coexist and let employees decide which applies
- Formally retire or update the older policy to eliminate the conflict (Correct answer)
- Apply the older policy since it was established first
- Escalate the conflict to an external auditor for resolution
Correct answer: Formally retire or update the older policy to eliminate the conflict
Conflicting policies create compliance confusion; the older document should be formally superseded, updated, or retired to maintain a coherent policy framework.
Which approach BEST supports consistent policy language across a large organization?