A mayor’s office wants distinct written policies for information security, business continuity, disaster recovery, incident response, secure development, and change control. Why separate them?
Select an answer to reveal the explanation.
Short Explanation
Different municipal risks need different rulebooks—IR playbooks are not the same as SDLC security or change-control gates. Separating information security, BCP, DR, IR, SDLC, and change-management policies keeps owners and duties clear. One vague mega-memo usually means nobody knows which section applies.
Full Explanation
Organizations maintain distinct policy types—information security, BCP, DR, IR, SDLC/security development, and change management—because each governs different processes, owners, and success criteria. Collapsing them into an unlabeled memo or leaving change undocumented weakens accountability. Mapping policy types to operational domains is a core governance practice.