ExamGecko
Question list
Search
Search

Question 517 - CISM discussion

Report
Export

Which of the following is the BEST indication of a mature information security program?

A.
Security incidents are managed properly.
Answers
A.
Security incidents are managed properly.
B.
Security spending is below budget.
Answers
B.
Security spending is below budget.
C.
Security resources are optimized.
Answers
C.
Security resources are optimized.
D.
Security audit findings are reduced.
Answers
D.
Security audit findings are reduced.
Suggested answer: C

Explanation:

A mature information security program is one that is aligned with the business strategy, objectives, and culture, and that delivers value to the organization by effectively managing the information security risks and enhancing the security posture. Optimizing the security resources means that the program uses the available human, financial, and technical resources in the most efficient and effective way, and that it continuously monitors and improves the performance and maturity of the security processes and controls.

Reference= CISM Review Manual 2022, page 331; CISM Exam Content Outline, Domain 1, Knowledge Statement 1.22;What is a Mature Information Security Program?;How to Measure the Maturity of Your Cybersecurity Program

asked 01/10/2024
Tatiana Castillo
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first