ExamGecko
Question list
Search
Search

Question 83 - CISM discussion

Report
Export

Which of the following BEST indicates that information security governance and corporate governance are integrated?

A.
The information security team is aware of business goals.
Answers
A.
The information security team is aware of business goals.
B.
The board is regularly informed of information security key performance indicators (KPIs),
Answers
B.
The board is regularly informed of information security key performance indicators (KPIs),
C.
The information security steering committee is composed of business leaders.
Answers
C.
The information security steering committee is composed of business leaders.
D.
A cost-benefit analysis is conducted on all information security initiatives.
Answers
D.
A cost-benefit analysis is conducted on all information security initiatives.
Suggested answer: C

Explanation:

The information security steering committee is composed of business leaders is the best indicator that information security governance and corporate governance are integrated, as this shows that the information security program is aligned with the business objectives and strategies, and that the information security manager has the support and involvement of the senior management. The information security steering committee is responsible for overseeing the information security program, setting the direction and scope, approving policies and standards, allocating resources, and monitoring performance and compliance. The information security steering committee also ensures that the information security risks are communicated and addressed at the board level, and that the information security program is consistent with the corporate governance framework and culture.The information security team is aware of business goals, the board is regularly informed of information security key performance indicators (KPIs), and a cost-benefit analysis is conducted on all information security initiatives are also important, but not as important as the information security steering committee is composed of business leaders, as they do not necessarily imply that the information security governance and corporate governance are integrated, and that the information security program has the authority and accountability to achieve its goals.Reference= CISM Review Manual 2023, page 271; CISM Review Questions, Answers & Explanations Manual 2023, page 342; ISACA CISM - iSecPrep, page 193

asked 01/10/2024
Luke Smith
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first