ExamGecko
Question list
Search
Search

Question 497 - CISM discussion

Report
Export

In order to gain organization-wide support for an information security program, which of the following is MOST important to consider?

A.
Maturity of the security policy
Answers
A.
Maturity of the security policy
B.
Clarity of security roles and responsibilities
Answers
B.
Clarity of security roles and responsibilities
C.
Corporate culture
Answers
C.
Corporate culture
D.
Corporate risk framework
Answers
D.
Corporate risk framework
Suggested answer: C

Explanation:

Corporate culture is the most important factor to consider when trying to gain organization-wide support for an information security program because it reflects the values, beliefs, and behaviors of the organization and its members. Corporate culture influences how the organization perceives, prioritizes, and responds to information security risks and issues, and how it adopts and implements information security policies and practices. By understanding and aligning with the corporate culture, the information security manager can communicate the benefits and value of the information security program, and foster a positive and collaborative security culture across the organization.

asked 01/10/2024
Roberto Garavaglia
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first