An organization is developing a security program that conveys the responsibilities associated with the general operation of systems and software within the organization. Which of the following documents would most likely communicate these expectations?
Choose an answer
Tap an option to check your answer.
Correct answer: Acceptable use policy.
Why this is the answer
An acceptable use policy (AUP) defines the proper way users can utilize an organization's IT assets, including systems and software. It clearly outlines user responsibilities and expected behavior, making it the most suitable document for communicating these operational expectations. A business continuity plan focuses on maintaining critical functions during disruptions, not daily operational responsibilities. A change management procedure details the process for implementing changes to IT systems, not general usage guidelines. A software development life cycle (SDLC) policy outlines the stages and security considerations for developing new software, not user responsibilities for existing systems.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed