ExamGecko
Question list
Search
Search

Question 543 - CISM discussion

Report
Export

Which of the following is the BEST indication that an organization has integrated information security governance with corporate governance?

A.
Security performance metrics are measured against business objectives.
Answers
A.
Security performance metrics are measured against business objectives.
B.
Impact is measured according to business loss when assessing IT risk.
Answers
B.
Impact is measured according to business loss when assessing IT risk.
C.
Security policies are reviewed whenever business objectives are changed.
Answers
C.
Security policies are reviewed whenever business objectives are changed.
D.
Service levels for security vendors are defined according to business needs.
Answers
D.
Service levels for security vendors are defined according to business needs.
Suggested answer: A

Explanation:

Security performance metrics are quantitative or qualitative measures that indicate the effectiveness and efficiency of the information security program in achieving the organization's security goals and objectives. Measuring security performance metrics against business objectives is the best indication that an organization has integrated information security governance with corporate governance, as it demonstrates that the security program is aligned with and supports the business strategy, value delivery, and risk management. (From CISM Review Manual 15th Edition)

asked 01/10/2024
Adrian Chirtoc
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first