ExamGecko
Question list
Search
Search

Question 506 - CISM discussion

Report
Export

Which of the following is MOST important to include in an information security strategy?

A.
Stakeholder requirements
Answers
A.
Stakeholder requirements
B.
Risk register
Answers
B.
Risk register
C.
Industry benchmarks
Answers
C.
Industry benchmarks
D.
Regulatory requirements
Answers
D.
Regulatory requirements
Suggested answer: A

Explanation:

Stakeholder requirements are the most important to include in an information security strategy, as they reflect the business needs, objectives, and expectations of the organization and its key stakeholders. Stakeholder requirements also help to align the information security strategy with the enterprise governance and the organizational culture. Risk register, industry benchmarks, and regulatory requirements are important inputs for the information security strategy, but they are not the most important to include.

Reference= CISM Review Manual 2022, page 321; CISM Exam Content Outline, Domain 1, Task 1.12

asked 01/10/2024
Chet Camlin
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first