ExamGecko
Question list
Search
Search

Question 504 - CISM discussion

Report
Export

Which of the following is MOST important to the effectiveness of an information security program?

A.
Security metrics
Answers
A.
Security metrics
B.
Organizational culture
Answers
B.
Organizational culture
C.
IT governance
Answers
C.
IT governance
D.
Risk management
Answers
D.
Risk management
Suggested answer: D

Explanation:

Risk management is the most important factor for the effectiveness of an information security program, as it provides a systematic and consistent approach to identify, assess, treat, and monitor the information security risks that could affect the organization's objectives. Risk management also helps to align the security program with the business strategy, prioritize the security initiatives and resources, and communicate the value of security to the stakeholders.

Reference= CISM Review Manual 2022, page 3071; CISM Exam Content Outline, Domain 4, Knowledge Statement 4.1

asked 01/10/2024
Welton Harris
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first