GRC Policy and Procedure Management 3 — Questions and Answers
Question 1: What distinguishes a procedure from a policy in the GRC policy hierarchy?
- Procedures are optional; policies are mandatory
- Procedures provide step-by-step instructions for implementing policies (Correct answer)
- Procedures are written by regulators; policies by management
- Procedures apply only to IT; policies apply organization-wide
Correct answer: Procedures provide step-by-step instructions for implementing policies
Procedures are operational documents that describe the specific steps employees must take to comply with higher-level policies.
Question 2: An organization publishes a new data classification policy but employees continue using the old scheme. What is the most likely root cause?
- The new policy was never formally approved
- Insufficient communication and training on the new policy (Correct answer)
- Data classification is inherently too complex
- The old scheme was mandated by regulators
Correct answer: Insufficient communication and training on the new policy
Without effective communication and training, employees lack awareness of policy changes and revert to familiar practices.
Question 3: Which governance body typically has final approval authority for enterprise-level security policies?
- The IT help desk team
- Individual department managers
- The Board of Directors or executive leadership (Correct answer)
- External auditors
Correct answer: The Board of Directors or executive leadership
Enterprise-level policies reflect organizational risk appetite and require Board or executive approval to carry appropriate authority.
Question 4: A policy states that access reviews must occur 'regularly.' Why is this language problematic?
- The word 'regularly' is too technical for most employees
- Vague language cannot be consistently audited or enforced (Correct answer)
- Access reviews should not be required by policy
- The term should be replaced with 'occasionally'
Correct answer: Vague language cannot be consistently audited or enforced
Vague terms like 'regularly' are not measurable, making it impossible to verify compliance or hold anyone accountable.
Question 5: When should a policy undergo an unscheduled review?
- Only when the annual review cycle arrives
- After a significant security incident, regulatory change, or major business change (Correct answer)
- Whenever an employee requests a review
- Only when auditors request it
Correct answer: After a significant security incident, regulatory change, or major business change
Trigger-based reviews ensure policies remain relevant when significant events occur between scheduled review cycles.
Question 6: What role does a policy management tool (software) play in a mature GRC program?
- It eliminates the need for policy owners
- It automates policy creation without human input
- It centralizes policy storage, version control, workflow, and attestation tracking (Correct answer)
- It replaces the need for a policy framework
Correct answer: It centralizes policy storage, version control, workflow, and attestation tracking
Policy management tools provide a single source of truth and automate lifecycle tasks like review reminders, approvals, and acknowledgment tracking.
Question 7: Which principle ensures that a policy is enforceable across the organization?
- The policy must be written in legal language only
- Senior management must visibly support and comply with the policy (Correct answer)
- Only IT personnel are required to follow the policy
- The policy must reference at least three external frameworks
Correct answer: Senior management must visibly support and comply with the policy
Management commitment and visible compliance signal that the policy applies equally to all levels, reinforcing its authority.
What distinguishes a procedure from a policy in the GRC policy hierarchy?