ExamGecko
Question list
Search
Search

Question 535 - CISM discussion

Report
Export

Which is MOST important to identify when developing an effective information security strategy?

A.
Security awareness training needs
Answers
A.
Security awareness training needs
B.
Potential savings resulting from security governance
Answers
B.
Potential savings resulting from security governance
C.
Business assets to be secured
Answers
C.
Business assets to be secured
D.
Residual risk levels
Answers
D.
Residual risk levels
Suggested answer: C

Explanation:

Business assets are the resources that enable the organization to achieve its objectives and create value. Identifying the business assets to be secured is the most important step in developing an effective information security strategy, as it helps to align the security goals with the business goals, prioritize the security efforts and resources, and define the scope and boundaries of the security program. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Ahmed Ebrahim
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first