ExamGecko
Question list
Search
Search

Question 389 - CISM discussion

Report
Export

Which of the following is MOST important to have in place for an organization's information security program to be effective?

A.
Documented information security processes
Answers
A.
Documented information security processes
B.
A comprehensive IT strategy
Answers
B.
A comprehensive IT strategy
C.
Senior management support
Answers
C.
Senior management support
D.
Defined and allocated budget
Answers
D.
Defined and allocated budget
Suggested answer: C

Explanation:

Senior management support is the most important factor to have in place for an organization's information security program to be effective because it helps to establish the vision, direction, and goals of the program, as well as to allocate the necessary resources and authority to implement and maintain it. Senior management support also helps to foster a security culture within the organization, where security is seen as a shared responsibility and a business enabler. Senior management support also helps to ensure compliance with internal and external security policies and standards, as well as to communicate the value and impact of security to stakeholders. Therefore, senior management support is the correct answer.

https://www.isaca.org/resources/isaca-journal/issues/2020/volume-6/key-performance-indicators-for-security-governance-part-1

https://www.ffiec.gov/press/PDF/FFIEC_IT_Handbook_Information_Security_Booklet.pdf

https://www.cdse.edu/Portals/124/Documents/student-guides/IF011-guide.pdf?ver=UA7IDZRN_y066rLB8oAW_w%3d%3d

asked 01/10/2024
Penny Chang
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first