MoIS4 CH04 Solutions
1. What is information security policy? Why it is critical to the success of the InfoSec program?
The Information Security Policy sets the strategic direction, scope, and tone for all of an
2. Of the controls or countermeasures used to control InfoSec risk, which is viewed as the least
expensive? What are the primary costs of this type of control?
Information Security Policies are the least costly to execute. The primary cost is management’s
3. List and describe the three challenges in shaping policy.
An organizations policy should never conflict with the law, it must stand up in court when it is
4. List and describe the three guidelines for sound policy, as stated by Bergeron and
Bérubé.
All policies must contribute to the success of an organization means that a policy should be
5. Describe the bull’s-eye model. What does it say about policy in the InfoSec program?
In the bull’s–eye model policies are on the outside, because policies should deal with every