Which Cybersecurity Policy Deficiency Is Most Critical?

Which of the following deficiencies identified during a review of an organization’s cybersecurity policy should be of MOST concern?

  1. The policy has gaps against relevant cybersecurity standards and frameworks.
  2. The policy lacks specifics on how to secure the organization's systems from cyberattacks.
  3. The policy has not been reviewed by the cybersecurity team in over a year.
  4. The policy has not been approved by the organization's board. Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests hierarchical policy governance, where candidates often fall into the trap of prioritizing technical control details over mandatory executive endorsement.

This CRISC question emphasizes the foundational role of executive governance in cybersecurity policies. Industry consensus confirms that missing board approval poses the greatest risk, as it directly undermines policy authority, funding, and organizational compliance.

Option B is frequently selected due to its technical focus, but detailed control specifications are meaningless without leadership backing to enforce them or allocate resources.

Community Discussion (4 comments)

d3a225d 👍 1 Selected: D
D. The policy has not been approved by the organization's board.
Sara98 👍 1 Selected: D
Board approval is crucial for demonstrating the organization's commitment to cybersecurity and ensuring that the policy aligns with the overall business strategy. A policy that has not been approved by the board may not be fully implemented or supported by senior management, which can weaken its effectiveness.
Jecalyn 👍 1 Selected: D
policy has not been approved should be the MOST concern
Joloms 👍 2
ll of the deficiencies mentioned are concerning, but the one that should be of MOST concern is: D. The policy has not been approved by the organization's board. Approval by the organization's board is crucial because it signifies high-level acknowledgment and commitment to the cybersecurity policy. Without board approval, the policy may lack the necessary authority, resources, and enforcement mechanisms to be effectively implemented throughout the organization. This deficiency indicates a fundamental gap in governance and oversight, which can undermine the organization's ability to effectively address cybersecurity risks.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Board approval establishes the formal mandate required for any cybersecurity policy to function effectively. It aligns security objectives with business strategy, secures essential funding, and grants enforcement authority across departments. In CRISC risk assessments, governance failures consistently rank above operational or technical gaps because they invalidate the entire control environment.

Why the Other Options Are Wrong

Gaps against industry standards (A) and missing technical specifics (B) are addressable through remediation plans once leadership provides direction and budget. Similarly, infrequent reviews (C) indicate poor maintenance but do not strip the policy of its foundational legitimacy. Without executive sponsorship, even perfectly documented technical controls cannot be implemented or sustained.

Community Comment Notes

Users consistently highlight that board approval demonstrates top-level accountability and commitment to cybersecurity priorities [1]. Several commenters stress that executive endorsement is required to overcome departmental resistance and ensure cross-functional compliance [3]. The discussion reinforces ISACA's principle that governance must precede all technical control design.

Official Reference

Exam Strategy

Always evaluate policy deficiencies through the lens of governance and strategic alignment before analyzing technical details. When faced with choices between executive sponsorship, funding, or legal compliance versus procedural gaps, prioritize the option that enables organizational enforcement.

Related Analysis

Practice All CRISC Questions

Access 332 questions with complete answers and detailed explanations.

View Full CRISC Practice Test →

← Back to CRISC Study Guide