ExamGecko
Question list
Search
Search

Question 211 - CISM discussion

Report
Export

Which of the following roles is BEST able to influence the security culture within an organization?

A.
Chief information security officer (CISO)
Answers
A.
Chief information security officer (CISO)
B.
Chief information officer (CIO)
Answers
B.
Chief information officer (CIO)
C.
Chief executive officer (CEO)
Answers
C.
Chief executive officer (CEO)
D.
Chief operating officer (COO)
Answers
D.
Chief operating officer (COO)
Suggested answer: C

Explanation:

The CEO is the best able to influence the security culture within an organization because the CEO sets the tone and direction for the organization and has the authority and responsibility to ensure that the organization's objectives are aligned with its strategy. The CEO can also communicate the importance and value of information security to all stakeholders and foster a culture of security awareness and accountability.The CISO, CIO and COO are important roles in information security management, but they do not have the same level of influence and authority as the CEO.Reference= CISM Review Manual, 16th Edition, page 221; CISM Exam Content Outline, Domain 1, Task 12

The Chief Information Security Officer (CISO) is responsible for leading and coordinating an organization's information security program, and as such, is in a prime position to influence the security culture within the organization. The CISO is responsible for setting policies and standards, educating employees about security risks and best practices, and ensuring that the organization is taking appropriate measures to mitigate security risks. By demonstrating a strong commitment to information security, the CISO can help to create a security-aware culture within the organization.

asked 01/10/2024
Michael Geary
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first