<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is more important, regulations or policy? in Exam Preparation</title>
    <link>https://community.isc2.org/t5/Exam-Preparation/What-is-more-important-regulations-or-policy/m-p/44145#M3510</link>
    <description>&amp;gt; gidyn (Newcomer III) posted a new topic in Exam Preparation on 03-22-2021 08:06&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I've seen variations on this crop up a few times in practice tests. The answers&lt;BR /&gt;&amp;gt; vary: - Policy, because that will include any applicable regulations. -&lt;BR /&gt;&amp;gt; Regulations, you have to follow the law even when it's in conflict with your&lt;BR /&gt;&amp;gt; policy. &amp;nbsp; What answer would you give if this came up in an exam, if "it&lt;BR /&gt;&amp;gt; depends" isn't one of the options?&lt;BR /&gt;&lt;BR /&gt;First off, I suspect that this is one of the "lazy" practice test questions: the&lt;BR /&gt;practice test people tend to try and make things hard by asking "trick" questions,&lt;BR /&gt;but not putting real work into wording the question so there is a real chance of it&lt;BR /&gt;making any sense.&lt;BR /&gt;&lt;BR /&gt;Secondly, my almost autonomic response is to say "policy," because when you are&lt;BR /&gt;faced with a difficult question, the "correct" answer is very often the&lt;BR /&gt;"management" answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Technically, regulation is part of regulatory law. Regulatory law only applies if&lt;BR /&gt;you are working in that specific field or industry. Therefore it will not apply&lt;BR /&gt;across the board, and, again, policy is more important.&lt;BR /&gt;&lt;BR /&gt;However, simply asking whether policy or regulation is more important is a bad&lt;BR /&gt;question, and you won't encounter that type of thing on the exam. Any question&lt;BR /&gt;that *does* address this type of issue will have additional background or factors&lt;BR /&gt;you need to consider.&lt;BR /&gt;&lt;BR /&gt;You owe the Oracle a regulation on how to write policy.&lt;BR /&gt;&lt;BR /&gt;======================&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;"If you do buy a computer, don't turn it on." - Richards' 2nd Law&lt;BR /&gt;"Robert Slade's Guide to Computer Viruses" 0-387-94663-2&lt;BR /&gt;"Viruses Revealed" 0-07-213090-3&lt;BR /&gt;"Software Forensics" 0-07-142804-6&lt;BR /&gt;"Dictionary of Information Security" Syngress 1-59749-115-2&lt;BR /&gt;"Cybersecurity Lessons from CoVID-19" CRC Press 978-0-367-68269-9&lt;BR /&gt;============= for back issues:&lt;BR /&gt;[Base URL] site &lt;A href="http://victoria.tc.ca/techrev/" target="_blank"&gt;http://victoria.tc.ca/techrev/&lt;/A&gt;&lt;BR /&gt;CISSP refs: [Base URL]mnbksccd.htm&lt;BR /&gt;PC Security: [Base URL]mnvrrvsc.htm&lt;BR /&gt;Security Dict.: [Base URL]secgloss.htm&lt;BR /&gt;Security Educ.: [Base URL]comseced.htm&lt;BR /&gt;Book reviews: [Base URL]mnbk.htm&lt;BR /&gt;[Base URL]review.htm&lt;BR /&gt;Partial/recent: &lt;A href="http://groups.yahoo.com/group/techbooks/" target="_blank"&gt;http://groups.yahoo.com/group/techbooks/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://en.wikipedia.org/wiki/Robert_Slade" target="_blank"&gt;http://en.wikipedia.org/wiki/Robert_Slade&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt; &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;</description>
    <pubDate>Mon, 22 Mar 2021 17:15:37 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2021-03-22T17:15:37Z</dc:date>
    <item>
      <title>What is more important, regulations or policy?</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/What-is-more-important-regulations-or-policy/m-p/44126#M3507</link>
      <description>&lt;P&gt;I've seen variations on this crop up a few times in practice tests. The answers vary:&lt;/P&gt;&lt;P&gt;- Policy, because that will include any applicable regulations.&lt;/P&gt;&lt;P&gt;- Regulations, you have to follow the law even when it's in conflict with your policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What answer would you give if this came up in an exam, if "it depends" isn't one of the options?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 12:06:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/What-is-more-important-regulations-or-policy/m-p/44126#M3507</guid>
      <dc:creator>gidyn</dc:creator>
      <dc:date>2021-03-22T12:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: What is more important, regulations or policy?</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/What-is-more-important-regulations-or-policy/m-p/44130#M3508</link>
      <description>&lt;P&gt;One where an organization or individual may be legally liable (party to a law petition, subject to fines,&amp;nbsp; imprisonment, or employee action). $00.02&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:42:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/What-is-more-important-regulations-or-policy/m-p/44130#M3508</guid>
      <dc:creator>RRoach</dc:creator>
      <dc:date>2021-03-22T13:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is more important, regulations or policy?</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/What-is-more-important-regulations-or-policy/m-p/44140#M3509</link>
      <description>&lt;P&gt;I use this to help me keep track of the hierarchy:&amp;nbsp;&lt;A href="https://www.complianceforge.com/word-crimes/policy-vs-standard-vs-control-vs-procedure" target="_blank" rel="noopener"&gt;https://www.complianceforge.com/word-crimes/policy-vs-standard-vs-control-vs-procedure&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just add 'Regulations' to the bottom of the pyramid as being the most important (or bare minimum depending on how you look at it). Also, depending on the type of policy, it doesn't have to reference a regulation to justify it's existence.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 15:24:17 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/What-is-more-important-regulations-or-policy/m-p/44140#M3509</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2021-03-22T15:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: What is more important, regulations or policy?</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/What-is-more-important-regulations-or-policy/m-p/44145#M3510</link>
      <description>&amp;gt; gidyn (Newcomer III) posted a new topic in Exam Preparation on 03-22-2021 08:06&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I've seen variations on this crop up a few times in practice tests. The answers&lt;BR /&gt;&amp;gt; vary: - Policy, because that will include any applicable regulations. -&lt;BR /&gt;&amp;gt; Regulations, you have to follow the law even when it's in conflict with your&lt;BR /&gt;&amp;gt; policy. &amp;nbsp; What answer would you give if this came up in an exam, if "it&lt;BR /&gt;&amp;gt; depends" isn't one of the options?&lt;BR /&gt;&lt;BR /&gt;First off, I suspect that this is one of the "lazy" practice test questions: the&lt;BR /&gt;practice test people tend to try and make things hard by asking "trick" questions,&lt;BR /&gt;but not putting real work into wording the question so there is a real chance of it&lt;BR /&gt;making any sense.&lt;BR /&gt;&lt;BR /&gt;Secondly, my almost autonomic response is to say "policy," because when you are&lt;BR /&gt;faced with a difficult question, the "correct" answer is very often the&lt;BR /&gt;"management" answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Technically, regulation is part of regulatory law. Regulatory law only applies if&lt;BR /&gt;you are working in that specific field or industry. Therefore it will not apply&lt;BR /&gt;across the board, and, again, policy is more important.&lt;BR /&gt;&lt;BR /&gt;However, simply asking whether policy or regulation is more important is a bad&lt;BR /&gt;question, and you won't encounter that type of thing on the exam. Any question&lt;BR /&gt;that *does* address this type of issue will have additional background or factors&lt;BR /&gt;you need to consider.&lt;BR /&gt;&lt;BR /&gt;You owe the Oracle a regulation on how to write policy.&lt;BR /&gt;&lt;BR /&gt;======================&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;"If you do buy a computer, don't turn it on." - Richards' 2nd Law&lt;BR /&gt;"Robert Slade's Guide to Computer Viruses" 0-387-94663-2&lt;BR /&gt;"Viruses Revealed" 0-07-213090-3&lt;BR /&gt;"Software Forensics" 0-07-142804-6&lt;BR /&gt;"Dictionary of Information Security" Syngress 1-59749-115-2&lt;BR /&gt;"Cybersecurity Lessons from CoVID-19" CRC Press 978-0-367-68269-9&lt;BR /&gt;============= for back issues:&lt;BR /&gt;[Base URL] site &lt;A href="http://victoria.tc.ca/techrev/" target="_blank"&gt;http://victoria.tc.ca/techrev/&lt;/A&gt;&lt;BR /&gt;CISSP refs: [Base URL]mnbksccd.htm&lt;BR /&gt;PC Security: [Base URL]mnvrrvsc.htm&lt;BR /&gt;Security Dict.: [Base URL]secgloss.htm&lt;BR /&gt;Security Educ.: [Base URL]comseced.htm&lt;BR /&gt;Book reviews: [Base URL]mnbk.htm&lt;BR /&gt;[Base URL]review.htm&lt;BR /&gt;Partial/recent: &lt;A href="http://groups.yahoo.com/group/techbooks/" target="_blank"&gt;http://groups.yahoo.com/group/techbooks/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://en.wikipedia.org/wiki/Robert_Slade" target="_blank"&gt;http://en.wikipedia.org/wiki/Robert_Slade&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt; &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;</description>
      <pubDate>Mon, 22 Mar 2021 17:15:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/What-is-more-important-regulations-or-policy/m-p/44145#M3510</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2021-03-22T17:15:37Z</dc:date>
    </item>
  </channel>
</rss>

