ExamGecko
Question list
Search
Search

Question 248 - CISM discussion

Report
Export

Which of the following is the BEST indication that an organization has a mature information security culture?

A.
Information security training is mandatory for all staff.
Answers
A.
Information security training is mandatory for all staff.
B.
The organization's information security policy is documented and communicated.
Answers
B.
The organization's information security policy is documented and communicated.
C.
The chief information security officer (CISO) regularly interacts with the board.
Answers
C.
The chief information security officer (CISO) regularly interacts with the board.
D.
Staff consistently consider risk in making decisions.
Answers
D.
Staff consistently consider risk in making decisions.
Suggested answer: D

Explanation:

The BEST indication that an organization has a mature information security culture is when its staff consistently consider risk in making decisions. When an organization's staff understands the risks associated with their actions and are empowered to make risk-informed decisions, it indicates that the organization has a mature information security culture.

According to the Certified Information Security Manager (CISM) Study Manual, 'A mature information security culture exists when the people within the organization understand and appreciate the risks associated with information and technology and when they take steps to manage those risks on a daily basis.'

While information security training, documented information security policies, and regular interaction between the chief information security officer (CISO) and the board are all important components of a mature information security culture, they are not sufficient on their own. It is only when staff consistently consider risk in making decisions that an organization's information security culture can be considered mature.

Certified Information Security Manager (CISM) Study Manual, 15th Edition, Pages 151-152.

asked 01/10/2024
Russell Bartsch
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first