ExamGecko
Question list
Search
Search

Question 542 - CISM discussion

Report
Export

Which of the following should be the PRIMARY focus of a status report on the information security program to senior management?

A.
Providing evidence that resources are performing as expected
Answers
A.
Providing evidence that resources are performing as expected
B.
Verifying security costs do not exceed the budget
Answers
B.
Verifying security costs do not exceed the budget
C.
Demonstrating risk is managed at the desired level
Answers
C.
Demonstrating risk is managed at the desired level
D.
Confirming the organization complies with security policies
Answers
D.
Confirming the organization complies with security policies
Suggested answer: C

Explanation:

The primary focus of a status report on the information security program to senior management is to demonstrate that the risk to the organization's information assets is managed at the desired level, in alignment with the business objectives and risk appetite. This can be achieved by providing relevant and meaningful metrics, indicators, and trends that show the performance, effectiveness, and value of the information security program, as well as the current and emerging risks and the corresponding mitigation strategies. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Edgar Alvarez
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first