ExamGecko
Question list
Search
Search

Question 149 - CISM discussion

Report
Export

A PRIMARY purpose of creating security policies is to:

A.
define allowable security boundaries.
Answers
A.
define allowable security boundaries.
B.
communicate management's security expectations.
Answers
B.
communicate management's security expectations.
C.
establish the way security tasks should be executed.
Answers
C.
establish the way security tasks should be executed.
D.
implement management's security governance strategy.
Answers
D.
implement management's security governance strategy.
Suggested answer: D

Explanation:

A security policy is a formal statement of the rules and principles that govern the protection of information assets in an organization. A security policy defines the scope, objectives, roles and responsibilities, and standards of the information security program. A primary purpose of creating security policies is to implement management's security governance strategy, which is the framework that guides the direction and alignment of information security with the business goals and objectives. A security policy translates the management's vision and expectations into specific and measurable requirements and controls that can be implemented and enforced by the information security staff and other stakeholders. A security policy also helps to establish the accountability and authority of the information security function and to demonstrate the commitment and support of the senior management for the information security program.

Reference=

CISM Review Manual 15th Edition, page 1631

CISM 2020: IT Security Policies2

CISM domain 1: Information security governance [Updated 2022]3

What is CISM?- Digital Guardian4

asked 01/10/2024
jim eagleton
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first