Back to Questions
CISA
QUESTION #1730
Question 1
What is the key distinction between an organisational policy and a procedure?
Correct Answer Explanation
A policy is a high-level directive, signed by a person of authority, that mandates a required outcome or standard of behaviour — compliance is not optional. A procedure is the lower-level, step-by-step operational document that prescribes exactly how the policy requirements are to be fulfilled in practice. Both are mandatory. This hierarchy — policy, standard, procedure, guideline — is fundamental to governance frameworks.
Sign in to join the conversation and share your thoughts.
Log In to Comment