ExamGecko
Question list
Search
Search

Question 624 - CISM discussion

Report
Export

Which of the following is the BEST way to determine the gap between the present and desired state of an information security program?

A.
Perform a risk analysis for critical applications.
Answers
A.
Perform a risk analysis for critical applications.
B.
Determine whether critical success factors (CSFs) have been defined.
Answers
B.
Determine whether critical success factors (CSFs) have been defined.
C.
Conduct a capability maturity model evaluation.
Answers
C.
Conduct a capability maturity model evaluation.
D.
Review and update current operational procedures.
Answers
D.
Review and update current operational procedures.
Suggested answer: C

Explanation:

A capability maturity model evaluation is the best way to determine the gap between the present and desired state of an information security program because it provides a systematic and structured approach to assess the current level of maturity of the information security processes and practices, and compare them with the desired or target level of maturity that is aligned with the business objectives and requirements. A capability maturity model evaluation can also help to identify the strengths and weaknesses of the information security program, prioritize the improvement areas, and develop a roadmap for achieving the desired state.

Reference=Information Security Architecture: Gap Assessment and Prioritization,CISM Review Manual 15th Edition

asked 01/10/2024
alex aguirre
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first