ExamGecko
Question list
Search
Search

Question 309 - CISM discussion

Report
Export

Which of the following is MOST important to have in place to help ensure an organization's cybersecurity program meets the needs of the business?

A.
Risk assessment program
Answers
A.
Risk assessment program
B.
Information security awareness training
Answers
B.
Information security awareness training
C.
Information security governance
Answers
C.
Information security governance
D.
Information security metrics
Answers
D.
Information security metrics
Suggested answer: C

Explanation:

= Information security governance is the process of establishing and maintaining the policies, standards, frameworks, and best practices that guide the information security program of an organization. Information security governance helps to ensure that the information security program meets the needs of the business by aligning it with the organization's risk appetite, objectives, and strategy. Information security governance also helps to coordinate and integrate various assurance functions, such as risk management, compliance, audit, and incident response, to provide a holistic view of the information security posture.Information security governance is essential for achieving a positive return on investment (ROI) from information security investments, as well as for enhancing the trust and confidence of internal and external stakeholders.References= CISM Review Manual (Digital Version), Chapter 1: Introduction to Information Security Management, Section 1.1: Overview of Information Security Management1.CISM Review Manual (Print Version), Chapter 1: Introduction to Information Security Management, Section 1.1: Overview of Information Security Management2. CISM ITEM DEVELOPMENT GUIDE, Domain 1: Information Security Governance, Task Statement 1.1, p.193.

Information security governance is MOST important to have in place to help ensure an organization's cybersecurity program meets the needs of the business. This is because information security governance provides the strategic direction, oversight and accountability for the cybersecurity program. It also ensures that the program aligns with the business objectives, risk appetite and compliance requirements of the organization. Information security governance involves defining roles and responsibilities, establishing policies and standards, setting goals and metrics, allocating resources and monitoring performance of the cybersecurity program.

asked 01/10/2024
Tracy Sampson
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first