ExamGecko
Question list
Search
Search

Question 499 - CISM discussion

Report
Export

Which of the following would be MOST helpful when creating information security policies?

A.
The information security framework
Answers
A.
The information security framework
B.
Business impact analysis (BIA)
Answers
B.
Business impact analysis (BIA)
C.
Information security metrics
Answers
C.
Information security metrics
D.
Risk assessment results
Answers
D.
Risk assessment results
Suggested answer: A

Explanation:

The information security framework is a set of principles, standards, guidelines, and best practices that define the scope, objectives, and requirements for information security in an organization. The information security framework is most helpful when creating information security policies because it provides a consistent and coherent approach to managing information security risks, aligning with business goals and strategy, and complying with relevant laws and regulations. The information security framework also helps to establish the roles, responsibilities, and accountability of all stakeholders involved in information security governance, management, and operations.

Reference= CISM Manual1, Chapter 3: Information Security Program Development (ISPD), Section 3.1: Information Security Framework2

1: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles2:1

asked 01/10/2024
Aiko Abrassart
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first