ExamGecko
Question list
Search
Search

Question 42 - CISM discussion

Report
Export

Which of the following messages would be MOST effective in obtaining senior management's commitment to information security management?

A.
Effective security eliminates risk to the business.
Answers
A.
Effective security eliminates risk to the business.
B.
Adopt a recognized framework with metrics.
Answers
B.
Adopt a recognized framework with metrics.
C.
Security is a business product and not a process.
Answers
C.
Security is a business product and not a process.
D.
Security supports and protects the business.
Answers
D.
Security supports and protects the business.
Suggested answer: D

Explanation:

The message that security supports and protects the business is the most effective in obtaining senior management's commitment to information security management. This message emphasizes the value and benefits of security for the organization's strategic goals, mission, and vision. It also aligns security with the business needs and expectations, and demonstrates how security can enable and facilitate the business processes and functions. The other messages are not as effective because they either overstate the role of security (A), focus on technical aspects rather than business outcomes (B), or confuse the nature and purpose of security .Reference=CISM Review Manual 2022, page 23;CISM Item Development Guide 2022, page 9;CISM Information Security Governance Certified Practice Exam - CherCherTech

asked 01/10/2024
Tyrome Myatt
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first