ExamGecko
Question list
Search
Search

Question 196 - CISM discussion

Report
Export

Which of the following BEST enables an organization to transform its culture to support information security?

A.
Periodic compliance audits
Answers
A.
Periodic compliance audits
B.
Strong management support
Answers
B.
Strong management support
C.
Robust technical security controls
Answers
C.
Robust technical security controls
D.
Incentives for security incident reporting
Answers
D.
Incentives for security incident reporting
Suggested answer: B

Explanation:

According to the CISM Review Manual (Digital Version), page 5, information security culture is the set of values, attitudes, and behaviors that shape how an organization and its employees view and practice information security.Transforming the information security culture requires a change management process that involves the following steps: creating a sense of urgency, forming a powerful coalition, developing a vision and strategy, communicating the vision, empowering broad-based action, generating short-term wins, consolidating gains and producing more change, and anchoring new approaches in the culture1. Among the four options, strong management support is the best enabler for transforming the information security culture, as it can provide the necessary leadership, resources, sponsorship, and alignment for the change management process.Periodic compliance audits, robust technical security controls, and incentives for security incident reporting are important elements of information security, but they are not sufficient to change the culture without strong management support.Reference=1: CISM Review Manual (Digital Version), page 5

asked 01/10/2024
Pay Ametovski
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first