ExamGecko
Question list
Search
Search

Question 602 - CISM discussion

Report
Export

Which of the following should be the PRIMARY objective when establishing a new information security program?

A.
Executing the security strategy
Answers
A.
Executing the security strategy
B.
Minimizing organizational risk
Answers
B.
Minimizing organizational risk
C.
Optimizing resources
Answers
C.
Optimizing resources
D.
Facilitating operational security
Answers
D.
Facilitating operational security
Suggested answer: A

Explanation:

According to the CISM Review Manual, the primary objective when establishing a new information security program is to execute the security strategy that has been defined and approved by the senior management. The security strategy provides the direction, scope, and goals for the information security program, and aligns with the business objectives and requirements. Minimizing organizational risk, optimizing resources, and facilitating operational security are possible outcomes or benefits of the information security program, but they are not the primary objective.

Reference= CISM Review Manual, 27th Edition, Chapter 3, Section 3.1.1, page 1151.

asked 01/10/2024
Khalid Laghmami
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first