ExamGecko
Question list
Search
Search

Question 2 - CISM discussion

Report
Export

Which of the following is MOST important to ensuring information stored by an organization is protected appropriately?

A.
Defining information stewardship roles
Answers
A.
Defining information stewardship roles
B.
Defining security asset categorization
Answers
B.
Defining security asset categorization
C.
Assigning information asset ownership
Answers
C.
Assigning information asset ownership
D.
Developing a records retention schedule
Answers
D.
Developing a records retention schedule
Suggested answer: C

Explanation:

The most important factor to ensuring information stored by an organization is protected appropriately is assigning information asset ownership. Information asset ownership is the process of identifying and assigning the roles and responsibilities of the individuals or groups who have the authority and accountability for the information assets and their protection. Information asset owners are responsible for defining the business value, classification, and security requirements of the information assets, as well as granting the access rights and privileges to the information users and custodians. Information asset owners are also responsible for monitoring and reviewing the security performance and compliance of the information assets, and reporting and resolving any security issues or incidents. By assigning information asset ownership, the organization can ensure that the information assets are properly identified, categorized, protected, and managed according to their importance, sensitivity, and regulatory obligations.

Reference= CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section: Data Classification, page 331; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 62, page 572.

asked 01/10/2024
Leandra Felipe
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first