ExamGecko
Question list
Search
Search

Question 209 - CISM discussion

Report
Export

Which of the following is the BEST approach to make strategic information security decisions?

A.
Establish regular information security status reporting.
Answers
A.
Establish regular information security status reporting.
B.
Establish an information security steering committee.
Answers
B.
Establish an information security steering committee.
C.
Establish business unit security working groups.
Answers
C.
Establish business unit security working groups.
D.
Establish periodic senior management meetings.
Answers
D.
Establish periodic senior management meetings.
Suggested answer: B

Explanation:

= According to the CISM Review Manual (Digital Version), page 9, an information security steering committee is a group of senior managers from different business units and functions who provide guidance and oversight for the information security program. An information security steering committee is the best approach to make strategic information security decisions because it can:

Ensure alignment of information security strategy with business objectives and risk appetite1

Facilitate communication and collaboration among different stakeholders and promote information security awareness and culture2

Provide direction and support for information security initiatives and projects3

Monitor and review the performance and effectiveness of the information security program4

Resolve conflicts and issues related to information security policies and practices5

Establishing regular information security status reporting, business unit security working groups, and periodic senior management meetings are useful activities for information security management, but they are not sufficient to make strategic information security decisions without the involvement and guidance of an information security steering committee.Reference=1: CISM Review Manual (Digital Version), page 92:13:24:35:4

An Information Security Steering Committee is a group of stakeholders responsible for providing governance and guidance to the organization on all matters related to information security. The committee provides oversight and guidance on security policies, strategies, and technology implementation. It also ensures that the organization is in compliance with relevant laws and regulations. Additionally, it serves as a forum for discussing security-related issues and ensures that security is taken into account when making strategic decisions.

asked 01/10/2024
Chris Ngobili
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first