ExamGecko
Question list
Search
Search

Question 408 - CISM discussion

Report
Export

Which of the following would BEST enable a new information security manager to obtain senior management support for an information security governance program?

A.
Demonstrating the program's value to the organization
Answers
A.
Demonstrating the program's value to the organization
B.
Discussing governance programs found in similar organizations
Answers
B.
Discussing governance programs found in similar organizations
C.
Providing the results of external audits
Answers
C.
Providing the results of external audits
D.
Providing examples of information security incidents within the organization
Answers
D.
Providing examples of information security incidents within the organization
Suggested answer: A

Explanation:

The best way to obtain senior management support for an information security governance program is to demonstrate the program's value to the organization, such as how it can help achieve business objectives, reduce operational risks, enhance resilience, and comply with regulations. Demonstrating the value of information security governance can help senior management understand the benefits and costs of the program, and motivate them to participate in the decision-making process. The other options, such as discussing governance programs in similar organizations, providing external audit results, or providing examples of incidents, may not be sufficient or persuasive enough to obtain senior management support, as they may not reflect the specific needs and goals of the organization.

Reference:

https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2020/how-to-involve-senior-management-in-the-information-security-governance-process

https://www.sans.org/white-papers/992/

https://www.govtech.com/blogs/lohrmann-on-cybersecurity/how-to-get-management-support-for-your-security-program.html

asked 01/10/2024
EDDIE LIN
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first