ExamGecko
Question list
Search
Search

Question 374 - CISM discussion

Report
Export

In addition to executive sponsorship and business alignment, which of the following is MOST critical for information security governance?

A.
Ownership of security
Answers
A.
Ownership of security
B.
Compliance with policies
Answers
B.
Compliance with policies
C.
Auditability of systems
Answers
C.
Auditability of systems
D.
Allocation of training resources
Answers
D.
Allocation of training resources
Suggested answer: A

Explanation:

Information security governance is the process of establishing and maintaining a framework to provide assurance that information security strategies are aligned with business objectives and consistent with applicable laws and regulations. In addition to executive sponsorship and business alignment, a critical factor for effective information security governance is ownership of security, which means that the roles and responsibilities for information security are clearly defined and assigned to the appropriate stakeholders, such as business owners, information owners, information custodians, and users. Ownership of security also implies accountability for the protection of information assets and the management of security risks.

Reference: https://www.isaca.org/credentialing/cism https://www.nist.gov/publications/information-security-handbook-guide-managers

asked 01/10/2024
David Clark
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first