ExamGecko
Question list
Search
Search

Question 4 - CISM discussion

Report
Export

Which of the following is the MOST important factor of a successful information security program?

A.
The program follows industry best practices.
Answers
A.
The program follows industry best practices.
B.
The program is based on a well-developed strategy.
Answers
B.
The program is based on a well-developed strategy.
C.
The program is cost-efficient and within budget,
Answers
C.
The program is cost-efficient and within budget,
D.
The program is focused on risk management.
Answers
D.
The program is focused on risk management.
Suggested answer: D

Explanation:

A successful information security program is one that aligns with the business objectives and strategy, supports the business processes and functions, and protects the information assets from threats and vulnerabilities. The most important factor of such a program is that it is focused on risk management, which means that it identifies, assesses, treats, and monitors the information security risks that could affect the business continuity, reputation, and value. Risk management helps to prioritize the security activities and resources, allocate the appropriate budget and resources, implement the necessary controls and measures, and evaluate the effectiveness and efficiency of the program. Risk management also enables the program to adapt to the changing business and threat environment, and to continuously improve the security posture and performance.A program that follows industry best practices, is based on a well-developed strategy, and is cost-efficient and within budget are all desirable attributes, but they are not sufficient to ensure the success of the program without a risk management focus.Reference= CISM Review Manual 15th Edition, page 411; CISM Practice Quiz, question 1242

asked 01/10/2024
tho nguyen
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first