ExamGecko
Question list
Search
Search

Question 659 - CISM discussion

Report
Export

An information security manager has been asked to provide both one-year and five-year plans for the information security program. What is the PRIMARY purpose for the long-term plan?

A.
To facilitate the continuous improvement of the IT organization
Answers
A.
To facilitate the continuous improvement of the IT organization
B.
To ensure controls align with security needs
Answers
B.
To ensure controls align with security needs
C.
To create and document required IT capabilities
Answers
C.
To create and document required IT capabilities
D.
To prioritize security risks on a longer scale than the one-year plan
Answers
D.
To prioritize security risks on a longer scale than the one-year plan
Suggested answer: B

Explanation:

The primary purpose for the long-term plan for the information security program is to ensure controls align with security needs. This is because the long-term plan provides a strategic vision and direction for the information security program, and defines the goals, objectives, and initiatives that support the organization's mission, vision, and values. The long-term plan also helps to identify and prioritize the security risks and opportunities that may arise in the future, and to align the information security controls with the changing business and technology environment. The long-term plan also facilitates the allocation and optimization of the resources and budget for the information security program, and enables the measurement and evaluation of the program's performance and value.

The long-term plan provides a strategic vision and direction for the information security program, and defines the goals, objectives, and initiatives that support the organization's mission, vision, and values. The long-term plan also helps to identify and prioritize the security risks and opportunities that may arise in the future, and to align the information security controls with the changing business and technology environment. (From CISM Manual or related resources)

Reference = CISM Review Manual 15th Edition, Chapter 3, Section 3.1.1, page 1261; CISM domain 3: Information security program development and management [2022 update] | Infosec2; CISM: Information Security Program Development and Management Part 1 Online, Self-Paced3

asked 01/10/2024
Kingsley Tibs
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first