ExamGecko
Question list
Search
Search

Question 638 - CISM discussion

Report
Export

Which of the following is MOST important when developing an information security strategy?

A.
Engage stakeholders.
Answers
A.
Engage stakeholders.
B.
Assign data ownership.
Answers
B.
Assign data ownership.
C.
Determine information types.
Answers
C.
Determine information types.
D.
Classify information assets.
Answers
D.
Classify information assets.
Suggested answer: A

Explanation:

Engaging stakeholders is the most important step when developing an information security strategy, as it ensures that the strategy is aligned with the business objectives, risks, and needs of the organization. Stakeholders include senior management, business units, IT staff, customers, regulators, and other relevant parties who have an interest or influence on the information security of the organization. By engaging stakeholders, the information security manager can gain their support, input, feedback, and buy-in for the strategy, as well as identify and prioritize the security requirements, expectations, and challenges.

Reference= CISM Review Manual, 27th Edition, Chapter 4, Section 4.1.1, page 2131; CISM Online Review Course, Module 4, Lesson 1, Topic 1

asked 01/10/2024
Sergy Camilo
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first