ExamGecko
Question list
Search
Search

Question 237 - CISM discussion

Report
Export

Which of the following should be the PRIMARY basis for an information security strategy?

A.
The organization's vision and mission
Answers
A.
The organization's vision and mission
B.
Results of a comprehensive gap analysis
Answers
B.
Results of a comprehensive gap analysis
C.
Information security policies
Answers
C.
Information security policies
D.
Audit and regulatory requirements
Answers
D.
Audit and regulatory requirements
Suggested answer: A

Explanation:

The organization's vision and mission should be the PRIMARY basis for an information security strategy, as they define the purpose and direction of the organization and its information security needs. A comprehensive gap analysis is a tool to identify the current state and desired state of information security, and the actions needed to close the gap. Information security policies are the high-level statements of management's intent and expectations for information security, and are derived from the information security strategy.Audit and regulatory requirements are external factors that influence the information security strategy, but are not the primary basis for it.Reference= CISM Review Manual, 16th Edition, pages 17-181; CISM Review Questions, Answers & Explanations Manual, 10th Edition, page 782

The primary basis for an information security strategy should be the organization's vision and mission. The organization's vision and mission should be the foundation for the security strategy, and should inform and guide the security policies, procedures, and practices that are implemented. The results of a comprehensive gap analysis, information security policies, and audit and regulatory requirements should all be taken into consideration when developing the security strategy, but should not be the primary basis.

asked 01/10/2024
Eric Zarghami
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first