GRC Policy and Procedure Management 5 — Questions and Answers
Question 1: An employee in a foreign subsidiary claims a corporate security policy violates local labor law. What should the GRC team do?
- Immediately revoke the policy globally
- Consult legal counsel to determine whether a jurisdictional exception or policy modification is needed (Correct answer)
- Ignore the concern since corporate policy supersedes local law
- Allow the subsidiary to opt out of all corporate policies
Correct answer: Consult legal counsel to determine whether a jurisdictional exception or policy modification is needed
Legal counsel must evaluate whether local law requires policy adaptation to avoid regulatory violations in that jurisdiction.
Question 2: Which document type provides the 'why' behind security requirements and sets management intent?
- Standard
- Procedure
- Policy (Correct answer)
- Guideline
Correct answer: Policy
Policies communicate management's intent and the organization's position on a topic without prescribing specific implementation steps.
Question 3: During an audit, the auditor requests evidence that the acceptable use policy was in effect 18 months ago. What is needed?
- The current version of the policy
- A screenshot of the current policy management system
- An archived version of the policy as it existed 18 months ago (Correct answer)
- A signed statement from the CISO
Correct answer: An archived version of the policy as it existed 18 months ago
Auditors assessing historical compliance need the exact policy version that was in effect during the period under review.
Question 4: What is the risk of setting policy review cycles longer than 3 years?
- Employees will become too familiar with the policies
- Policies may become misaligned with evolving threats, regulations, and business changes (Correct answer)
- The legal team will have too little work
- Policies will become too specific over time
Correct answer: Policies may become misaligned with evolving threats, regulations, and business changes
Long review cycles increase the likelihood that policies will not reflect current threats, technologies, or regulatory requirements.
Question 5: A guidelines document says employees 'should' encrypt sensitive emails. What does this language indicate?
- Encryption is mandatory and will be technically enforced
- Encryption is a recommended practice but not required (Correct answer)
- Encryption violates company policy
- The guideline has legal standing equal to a policy
Correct answer: Encryption is a recommended practice but not required
The word 'should' indicates a recommendation rather than a mandatory control, distinguishing guidelines from standards and policies.
Question 6: Which of the following best supports policy adoption in a decentralized organization with multiple business units?
- Mandate that every business unit write its own independent policies
- Develop enterprise-wide policies with business unit-specific annexes or supplements (Correct answer)
- Allow each business unit to opt out of policies that are inconvenient
- Issue policies only through the legal department without GRC involvement
Correct answer: Develop enterprise-wide policies with business unit-specific annexes or supplements
A federated approach with enterprise core policies and business unit supplements balances consistency with operational flexibility.
Question 7: What is the significance of a 'policy effective date' separate from the approval date?
- It has no practical significance in policy management
- It provides time for communication, training, and system changes before compliance is required (Correct answer)
- It delays accountability for policy owners
- It is required only by international regulations
Correct answer: It provides time for communication, training, and system changes before compliance is required
An effective date after the approval date allows the organization to prepare employees and systems before enforcement begins.
An employee in a foreign subsidiary claims a corporate security policy violates local labor law.
What should the GRC team do?