ExamGecko
Question list
Search
Search

Question 88 - CISM discussion

Report
Export

Which of the following is the MOST effective way to help staff members understand their responsibilities for information security?

A.
Communicate disciplinary processes for policy violations.
Answers
A.
Communicate disciplinary processes for policy violations.
B.
Require staff to participate in information security awareness training.
Answers
B.
Require staff to participate in information security awareness training.
C.
Require staff to sign confidentiality agreements.
Answers
C.
Require staff to sign confidentiality agreements.
D.
Include information security responsibilities in job descriptions.
Answers
D.
Include information security responsibilities in job descriptions.
Suggested answer: B

Explanation:

The most effective way to help staff members understand their responsibilities for information security is to require them to participate in information security awareness training. Information security awareness training is a program that educates and motivates the staff members about the importance, benefits, and principles of information security, and the roles and responsibilities that they have in protecting the information assets and resources of the organization. Information security awareness training also provides the staff members with the necessary knowledge, skills, and tools to comply with the information security policies, procedures, and standards of the organization, and to prevent, detect, and report any information security incidents or issues. Information security awareness training also helps to create and maintain a positive and proactive information security culture among the staff members, and to increase their confidence and competence in performing their information security duties.

Reference= CISM Review Manual, 16th Edition, Chapter 1: Information Security Governance, Section: Information Security Culture, page 281; CISM Review Manual, 16th Edition, Chapter 3: Information Security Program Development and Management, Section: Information Security Awareness, Training and Education, pages 197-1982.

asked 01/10/2024
Kanta Prasad
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first