IGP Information Governance Framework & Policies 2 — Questions and Answers
Question 1: Which standard provides a globally recognized framework specifically for information security management systems (ISMS)?
- COBIT 5
- ISO/IEC 27001 (Correct answer)
- NIST SP 800-53
- ARMA Generally Accepted Recordkeeping Principles
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS.
Question 2: In an IG framework, a 'policy' differs from a 'procedure' primarily because a policy:
- Describes step-by-step instructions for task completion
- States the organization's intent and high-level rules (Correct answer)
- Assigns specific roles to named individuals
- Defines technical configurations for IT systems
Correct answer: States the organization's intent and high-level rules
Policies express organizational intent and mandatory rules, while procedures provide the step-by-step instructions for implementing those policies.
Question 3: The ARMA International Generally Accepted Recordkeeping Principles (GARP) include how many core principles?
- 6
- 8 (Correct answer)
- 10
- 12
Correct answer: 8
ARMA's GARP framework consists of 8 core principles: Accountability, Transparency, Integrity, Protection, Compliance, Availability, Retention, and Disposition.
Question 4: When developing an IG policy for email, which element is MOST critical to include to ensure legal defensibility?
- Font size and formatting requirements
- Retention schedule aligned with legal holds and regulations (Correct answer)
- Employee personal email usage limits
- Email server vendor specifications
Correct answer: Retention schedule aligned with legal holds and regulations
A legally defensible email policy must include retention schedules that align with applicable regulations and the organization's legal hold obligations.
Question 5: Which governance body is typically responsible for approving enterprise-level IG policies?
- IT Help Desk
- Individual department managers
- Executive leadership or a steering committee (Correct answer)
- External auditors
Correct answer: Executive leadership or a steering committee
Enterprise IG policies require approval at the executive or steering committee level to ensure enterprise-wide authority and cross-departmental compliance.
Question 6: A gap analysis in IG framework development is used to:
- Calculate the cost of IG technology investments
- Identify differences between the current state and desired IG program maturity (Correct answer)
- Train employees on records management procedures
- Audit vendor compliance with data sharing agreements
Correct answer: Identify differences between the current state and desired IG program maturity
A gap analysis compares the organization's current IG capabilities and practices against its desired or required state to prioritize improvements.
Question 7: Under the principle of 'least privilege' in information governance, access to sensitive information should be granted:
- To all employees to maximize productivity
- Only to the minimum number of users required to perform their job functions (Correct answer)
- Based on seniority and years of service
- At the discretion of each department head without central oversight
Correct answer: Only to the minimum number of users required to perform their job functions
Least privilege limits information access to only those who need it to perform their duties, reducing the risk of unauthorized disclosure or misuse.
Which standard provides a globally recognized framework specifically for information security management systems (ISMS)?