ExamGecko
Question list
Search
Search

Question 448 - CISM discussion

Report
Export

Which of the following is the MOST important constraint to be considered when developing an information security strategy?

A.
Legal and regulatory requirements
Answers
A.
Legal and regulatory requirements
B.
Established security policies and standards
Answers
B.
Established security policies and standards
C.
Compliance with an international security standard
Answers
C.
Compliance with an international security standard
D.
Information security architecture
Answers
D.
Information security architecture
Suggested answer: A

Explanation:

Legal and regulatory requirements are the most important constraint to be considered when developing an information security strategy, as they define the minimum level of security that the organization must comply with to avoid legal sanctions, fines, or reputational damage.Legal and regulatory requirements may vary depending on the jurisdiction, industry, and type of data that the organization handles, and they may impose specific security controls, standards, or frameworks that the organization must follow.Reference= CISM Review Manual, 16th Edition, Chapter 1, Section 1.2.1.11

asked 01/10/2024
Saphronia Yancey
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first