ExamGecko
Question list
Search
Search

Question 473 - CISM discussion

Report
Export

Which of the following is the MOST important consideration when briefing executives about the current state of the information security program?

A.
Including a situational forecast
Answers
A.
Including a situational forecast
B.
Using appropriate language for the target audience
Answers
B.
Using appropriate language for the target audience
C.
Including trend charts for metrics
Answers
C.
Including trend charts for metrics
D.
Using a rating system to demonstrate program effectiveness
Answers
D.
Using a rating system to demonstrate program effectiveness
Suggested answer: B

Explanation:

= When briefing executives about the current state of the information security program, the most important consideration is to use appropriate language for the target audience. This means avoiding technical jargon, acronyms, and details that may confuse or bore the executives, and instead focusing on the business value, risks, and benefits of the information security program. The other options are not as important or relevant as using appropriate language, although they may also be useful to include in the briefing. For example, a situational forecast may be helpful to show the future trends and challenges, but it is not as essential as communicating the current state clearly and concisely. Similarly, trend charts for metrics and a rating system to demonstrate program effectiveness may be useful to support the briefing, but they are not as critical as using language that the executives can understand and relate to.Reference=

Information Security Guide for Government Executives, page 7: ''Reminding employees of their responsibilities and demonstrating management's commitment to the security program are key to maintaining effective security within the constantly changing information security environment.''

Information security guide for government executives - NIST, page 3: ''The executive should communicate the importance of information security to the organization and its staff, using language that is meaningful to the target audience.''

Information Security Committee Charter - SecurityStudio, page 1: ''The committee also coordinates and communicates the direction, current state, and oversight of the information security program.''

asked 01/10/2024
Ghalem benhameurlaine
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first