ExamGecko
Question list
Search
Search

Question 22 - CISM discussion

Report
Export

Which of the following BEST ensures information security governance is aligned with corporate governance?

A.
A security steering committee including IT representation
Answers
A.
A security steering committee including IT representation
B.
A consistent risk management approach
Answers
B.
A consistent risk management approach
C.
An information security risk register
Answers
C.
An information security risk register
D.
Integration of security reporting into corporate reporting
Answers
D.
Integration of security reporting into corporate reporting
Suggested answer: D

Explanation:

The best way to ensure information security governance is aligned with corporate governance is to integrate security reporting into corporate reporting. This will enable the board and senior management to oversee and monitor the performance and effectiveness of the information security program, as well as the alignment of information security objectives and strategies with business goals and risk appetite. Security reporting should provide relevant, timely, accurate, and actionable information to support decision making and accountability.The other options are important components of information security governance, but they do not ensure alignment with corporate governance by themselves.Reference= CISM Review Manual 15th Edition, page 411; CISM Review Questions, Answers & Explanations Database - 12 Month Subscription, Question ID: 1027

asked 01/10/2024
Terry Mergl
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first