ExamGecko
Question list
Search
Search

Question 29 - CISM discussion

Report
Export

Which of the following is MOST important to have in place as a basis for developing an effective information security program that supports the organization's business goals?

A.
Metrics to drive the information security program
Answers
A.
Metrics to drive the information security program
B.
Information security policies
Answers
B.
Information security policies
C.
A defined security organizational structure
Answers
C.
A defined security organizational structure
D.
An information security strategy
Answers
D.
An information security strategy
Suggested answer: D

Explanation:

An information security strategy is the most important element to have in place as a basis for developing an effective information security program that supports the organization's business goals.An information security strategy is a high-level plan that defines the vision, mission, objectives, scope, and principles of information security for the organization1.It also aligns the information security program with the organization's strategy, culture, risk appetite, and governance framework2.An information security strategy provides the direction, guidance, and justification for the information security program, and ensures that the program is consistent, coherent, and comprehensive3.An information security strategy also helps to prioritize the information security initiatives, allocate the resources, and measure the performance and value of the information security program4.

The other options are not as important as an information security strategy, because they are either derived from or dependent on the strategy. Metrics are used to drive the information security program, but they need to be based on the strategy and aligned with the goals and objectives of the program. Information security policies are the rules and standards that implement the information security strategy and define the expected behavior and responsibilities of the stakeholders.A defined security organizational structure is the way the information security roles and functions are organized and coordinated within the organization, and it should reflect the strategy and the governance model.Reference=1: CISM Review Manual 15th Edition, Chapter 1, Section 1.12: CISM Review Manual 15th Edition, Chapter 1, Section 1.23: CISM Review Manual 15th Edition, Chapter 1, Section 1.34: CISM Review Manual 15th Edition, Chapter 1, Section 1.4 : CISM Review Manual 15th Edition, Chapter 1, Section 1.5 : CISM Review Manual 15th Edition, Chapter 1, Section 1.6 : CISM Review Manual 15th Edition, Chapter 1, Section 1.7

asked 01/10/2024
Kwame Kankam-Boadu
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first