For a policy to have any effect, what must happen after it is approved by management?
What are some ways to accomplish this? Is policy considered static or dynamic?
Which factors might determine this status? List and describe the three types of InfoSec policy as described by NIST SP 800-14.