ExamGecko
Question list
Search
Search

Question 249 - CISM discussion

Report
Export

What is the PRIMARY benefit to an organization that maintains an information security governance framework?

A.
Resources are prioritized to maximize return on investment (ROI)
Answers
A.
Resources are prioritized to maximize return on investment (ROI)
B.
Information security guidelines are communicated across the enterprise_
Answers
B.
Information security guidelines are communicated across the enterprise_
C.
The organization remains compliant with regulatory requirements.
Answers
C.
The organization remains compliant with regulatory requirements.
D.
Business risks are managed to an acceptable level.
Answers
D.
Business risks are managed to an acceptable level.
Suggested answer: D

Explanation:

According to the Certified Information Security Manager (CISM) Study Manual, a mature information security culture is one in which staff members regularly consider risk in their decisions. This means that they are aware of the risks associated with their actions and take preventative steps to reduce the likelihood of negative outcomes. Other indicators of a mature information security culture include mandatory information security training for all staff, documented and communicated information security policies, and regular interaction between the CISO and the board.

Maintaining an information security governance framework enables an organization to identify, assess, and manage its information security risks. By establishing policies, procedures, and controls that are aligned with the organization's objectives and risk tolerance, an information security governance framework helps ensure that information security risks are managed to an acceptable level.

According to the Certified Information Security Manager (CISM) Study Manual, 'Information security governance provides a framework for managing and controlling information security practices and technologies at an enterprise level. Its primary objective is to manage and reduce risk through a process of identification, assessment, and management of those risks.'

While the other options listed (prioritizing resources, communicating guidelines, and remaining compliant with regulations) are also important benefits of maintaining an information security governance framework, they are all secondary to the primary benefit of managing business risks to an acceptable level.

Certified Information Security Manager (CISM) Study Manual, 15th Edition, Pages 60-63.

asked 01/10/2024
vinoth inigo
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first