Which two are the best guidance to follow when creating the policy?
An organization is creating a policy for logging and managing a wide variety of incidents. The organization operates in a highly regulated environment it is essential that the policy is adhered to and that deviations are considered unacceptable. Which two are the best guidance to follow when creating the policy?
1. Ensure that the policy is as flexible as possible to allow staff to make decisions freely
2. Ensure that the policy is as clear and concise as possible stating why it is necessary
3. Ensure that the consequences of noncompliance are clearly stated
4. Ensure that the process is automated in order to minimize the controls included in the policy
OPTIONS
- 1 and 2
- 2 and 3
- 3 and 4
- 1 and 4
ANSWER
2 and 3
EXPLANATION
(2) Recommendations of effective policies include ensuring they are clear and concise. A policy must be understandable for it to be followed. Alongside the policy itself document, as clearly and concisely as possible, its objective and scope and why it matters to the organization. (3) Recommendations of effective policies include ensuring that the consequences of noncompliance are clear. This is particularly relevant in this case. The consequences of failing to follow a policy should be documented. These consequences must then be administered consistently and fairly to prevent the policy from being ignored.