ExamGecko
Question list
Search
Search

Question 11 - CISM discussion

Report
Export

Which of the following is the BEST evidence of alignment between corporate and information security governance?

A.
Security key performance indicators (KPIs)
Answers
A.
Security key performance indicators (KPIs)
B.
Project resource optimization
Answers
B.
Project resource optimization
C.
Regular security policy reviews
Answers
C.
Regular security policy reviews
D.
Senior management sponsorship
Answers
D.
Senior management sponsorship
Suggested answer: D

Explanation:

Alignment between corporate and information security governance means that the information security program supports the organizational goals and objectives, and is integrated into the enterprise governance structure. The best evidence of alignment is the senior management sponsorship, which demonstrates the commitment and support of the top-level executives and board members for the information security program. Senior management sponsorship also ensures that the information security program has adequate resources, authority, and accountability to achieve its objectives and address the risks and issues that affect the organization. Senior management sponsorship also helps to establish a culture of security awareness and compliance throughout the organization, and to communicate the value and benefits of the information security program to the stakeholders.

Reference=

CISM Review Manual 15th Edition, page 1631

CISM 2020: Information Security & Business Process Alignment, video 22

Certified Information Security Manager (CISM), page 33

asked 01/10/2024
Marcel Bertz
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first