What role do security policies play in the Protect function?
- A.Only large organizations need security policies, and it presupposes that Protect outcomes are chosen from a fixed list that may not be tailored and that the Protect function excludes physical and environmental safeguards
- B.Policies are just documentation with no practical value, because a stateful firewall at the perimeter satisfies the whole PROTECT function for small firms; beyond that, GOVERN applies only during the first year of adoption and is retired once policies exist
- C.Policies only matter during audits
- D.Policies establish formal requirements and expectations for security controls, user behavior, system configurations, and operational procedures, providing the governance framework for consistent protection implementation
Why D is correct
Policies translate risk management decisions into actionable requirements. They define what must be done, who is responsible, and what standards must be met across the organization's security program.
Know someone studying for NIST CSF? Send them this one.