ExamGecko
Question list
Search
Search

Question 75 - CISM discussion

Report
Export

Which of the following is the BEST indication ofa successful information security culture?

A.
Penetration testing is done regularly and findings remediated.
Answers
A.
Penetration testing is done regularly and findings remediated.
B.
End users know how to identify and report incidents.
Answers
B.
End users know how to identify and report incidents.
C.
Individuals are given roles based on job functions.
Answers
C.
Individuals are given roles based on job functions.
D.
The budget allocated for information security is sufficient.
Answers
D.
The budget allocated for information security is sufficient.
Suggested answer: B

Explanation:

The best indication of a successful information security culture is that end users know how to identify and report incidents. This shows that the end users are aware of the information security policies, procedures, and practices of the organization, and that they understand their roles and responsibilities in protecting the information assets and resources. It also shows that the end users are engaged and committed to the information security goals and objectives of the organization, and that they are willing to cooperate and collaborate with the information security team and other stakeholders in preventing, detecting, and responding to information security incidents.A successful information security culture is one that fosters a positive attitude and behavior toward information security among all members of the organization, and that aligns the information security strategy with the business strategy and the organizational culture1.

Reference= CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section: Information Security Culture, page 281.

asked 01/10/2024
Alexis Chacon
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first