ExamGecko
Question list
Search
Search

Question 267 - CISM discussion

Report
Export

Which of the following is the MOST critical factor for information security program success?

A.
comprehensive risk assessment program for information security
Answers
A.
comprehensive risk assessment program for information security
B.
The information security manager's knowledge of the business
Answers
B.
The information security manager's knowledge of the business
C.
Security staff with appropriate training and adequate resources
Answers
C.
Security staff with appropriate training and adequate resources
D.
Ongoing audits and addressing open items
Answers
D.
Ongoing audits and addressing open items
Suggested answer: B

Explanation:

The explanation given in the manual is:

The information security manager's knowledge of the business is the most critical factor for information security program success because it enables him or her to align security objectives with business goals and communicate effectively with senior management and other stakeholders. The other choices are important elements of an information security program but not as critical as the information security manager's knowledge of the business.

An information security program is a set of policies, procedures, standards, guidelines, and tools that aim to protect an organization's information assets from threats and ensure compliance with laws and regulations. An information security manager is a professional who oversees and coordinates the implementation and maintenance of an information security program. An information security manager should have a good understanding of the business environment, culture, strategy, processes, and needs of an organization to ensure that security supports its objectives.

asked 01/10/2024
saiming wong
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first