ExamGecko
Question list
Search
Search

Question 63 - CISM discussion

Report
Export

Reviewing which of the following would be MOST helpful when a new information security manager is developing an information security strategy for a non-regulated organization?

A.
Management's business goals and objectives
Answers
A.
Management's business goals and objectives
B.
Strategies of other non-regulated companies
Answers
B.
Strategies of other non-regulated companies
C.
Risk assessment results
Answers
C.
Risk assessment results
D.
Industry best practices and control recommendations
Answers
D.
Industry best practices and control recommendations
Suggested answer: A

Explanation:

When a new information security manager is developing an information security strategy for a non-regulated organization, reviewing the management's business goals and objectives would be the most helpful. This is because the information security strategy should be aligned with and support the organization's vision, mission, values, and strategic direction. The information security strategy should also enable the organization to achieve its desired outcomes, such as increasing revenue, reducing costs, enhancing customer satisfaction, or improving operational efficiency. By reviewing the management's business goals and objectives, the information security manager can understand the business context, needs, and expectations of the organization, and design the information security strategy accordingly. The information security manager can also communicate the value proposition and benefits of the information security strategy to the management and other stakeholders, and gain their support and commitment.

Reference= CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section: Information Security Strategy, page 211; CISM Review Questions, Answers & Explanations Manual, 10th Edition, Question 48, page 452.

asked 01/10/2024
Hoang Son
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first