ExamGecko
Question list
Search
Search

Question 401 - CISM discussion

Report
Export

Which of the following is MOST important when defining how an information security budget should be allocated?

A.
Regulatory compliance standards
Answers
A.
Regulatory compliance standards
B.
Information security strategy
Answers
B.
Information security strategy
C.
Information security policy
Answers
C.
Information security policy
D.
Business impact assessment
Answers
D.
Business impact assessment
Suggested answer: B

Explanation:

Information security strategy is the most important factor when defining how an information security budget should be allocated because it helps to align the security objectives and initiatives with the business goals and priorities. An information security strategy is a high-level plan that defines the vision, mission, scope, and direction of the security program, as well as the roles and responsibilities, governance structures, policies and standards, risk management approaches, and performance measurement methods. An information security strategy helps to identify and prioritize the security needs and requirements of the organization, as well as to allocate the resources and funding accordingly. An information security strategy also helps to communicate the value and benefits of security to the stakeholders and justify the security investments. Therefore, information security strategy is the correct answer.

https://www.techtarget.com/searchsecurity/tip/Cybersecurity-budget-breakdown-and-best-practices

https://www.csoonline.com/article/3671108/how-2023-cybersecurity-budget-allocations-are-shaping-up.html

https://www.statista.com/statistics/1319677/companies-it-budget-allocated-to-security-worldwide/

asked 01/10/2024
Chet Camlin
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first