ExamGecko
Question list
Search
Search

Question 323 - CISM discussion

Report
Export

Which of the following BEST enables an information security manager to obtain organizational support for the implementation of security controls?

A.
Conducting periodic vulnerability assessments
Answers
A.
Conducting periodic vulnerability assessments
B.
Communicating business impact analysis (BIA) results
Answers
B.
Communicating business impact analysis (BIA) results
C.
Establishing effective stakeholder relationships
Answers
C.
Establishing effective stakeholder relationships
D.
Defining the organization's risk management framework
Answers
D.
Defining the organization's risk management framework
Suggested answer: C

Explanation:

The best way to obtain organizational support for the implementation of security controls is to establish effective stakeholder relationships. Stakeholders are the individuals or groups that have an interest or influence in the organization's information security objectives, activities, and outcomes. They may include senior management, business owners, users, customers, regulators, auditors, vendors, and others. By establishing effective stakeholder relationships, the information security manager can communicate the value and benefits of security controls to the organization's performance, reputation, and competitiveness. The information security manager can also solicit feedback and input from stakeholders to ensure that the security controls are aligned with the organization's needs and expectations. The information security manager can also foster collaboration and cooperation among stakeholders to facilitate the implementation and operation of security controls. The other options are not the best way to obtain organizational support for the implementation of security controls, although they may be some steps or outcomes of the process. Conducting periodic vulnerability assessments is a technical activity that can help identify and prioritize the security weaknesses and gaps in the organization's information assets and systems. However, it does not necessarily obtain organizational support for the implementation of security controls unless the results are communicated and justified to the stakeholders. Communicating business impact analysis (BIA) results is a reporting activity that can help demonstrate the potential consequences of disruptions or incidents on the organization's critical business processes and functions. However, it does not necessarily obtain organizational support for the implementation of security controls unless the results are linked to the organization's risk appetite and tolerance. Defining the organization's risk management framework is a strategic activity that can help establish the policies, procedures, roles, and responsibilities for managing information security risks in a consistent and effective manner. However, it does not necessarily obtain organizational support for the implementation of security controls unless the framework is endorsed and enforced by the stakeholders

asked 01/10/2024
Priyantha Perea
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first