ExamGecko
Question list
Search
Search

Question 610 - CISM discussion

Report
Export

Which of the following BEST facilitates the development of a comprehensive information security policy?

A.
Alignment with an established information security framework
Answers
A.
Alignment with an established information security framework
B.
An established internal audit program
Answers
B.
An established internal audit program
C.
Security key performance indicators (KPIs)
Answers
C.
Security key performance indicators (KPIs)
D.
Areview of recent information security incidents
Answers
D.
Areview of recent information security incidents
Suggested answer: A

Explanation:

Alignment with an established information security framework is the BEST way to facilitate the development of a comprehensive information security policy, because it provides a consistent and structured approach to define, implement, and maintain the policy across the organization. An information security framework is a set of best practices, standards, and guidelines that help to ensure the effectiveness, efficiency, and compliance of the information security policy.

Reference=

CISM Review Manual, 16th Edition, ISACA, 2020, p. 35: ''An information security framework is a set of best practices, standards, and guidelines that provide a consistent and structured approach to information security governance.''

CISM Review Manual, 16th Edition, ISACA, 2020, p. 36: ''The information security policy should be aligned with an established information security framework to ensure its effectiveness, efficiency, and compliance.''

asked 01/10/2024
sd sdg
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first