ExamGecko
Question list
Search
Search

Question 463 - CISM discussion

Report
Export

Which of the following should be the PRIMARY outcome of an information security program?

A.
Strategic alignment
Answers
A.
Strategic alignment
B.
Risk elimination
Answers
B.
Risk elimination
C.
Cost reduction
Answers
C.
Cost reduction
D.
Threat reduction
Answers
D.
Threat reduction
Suggested answer: A

Explanation:

According to the CISM Review Manual (Digital Version), Chapter 3, Section 3.2.1, strategic alignment is the primary outcome of an information security program1.Strategic alignment means that the information security program supports and is tailored to the organization's objectives and business strategy1.It also means that the information security program is aligned with other assurance functions, such as physical, human resources, quality, and IT1.

The CISM Review Manual (Digital Version) also states that strategic alignment is essential for achieving a competitive advantage, enhancing customer trust, reducing legal and regulatory risks, and improving organizational performance1.Strategic alignment requires effective communication and collaboration among all stakeholders, including senior management, information owners, information security managers, information security steering committees, and external partners1.

The CISM Exam Content Outline also covers the topic of strategic alignment in Domain 3 --- Information Security Program Development and Management (33% exam weight)2. The subtopics include:

3.2.1 Information Security Strategy

3.2.2 Information Security Governance

3.2.3 Information Security Risk Management

3.2.4 Information Security Compliance

I hope this answer helps you prepare for your CISM exam. Good luck!

asked 01/10/2024
Nabil BENIKHLEF
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first