ExamGecko
Question list
Search
Search

Question 671 - CISM discussion

Report
Export

Which of the following is the BEST reason to implement a comprehensive information security management system?

A.
To ensure continuous alignment with the organizational strategy
Answers
A.
To ensure continuous alignment with the organizational strategy
B.
To gain senior management support for the information security program
Answers
B.
To gain senior management support for the information security program
C.
To support identification of key risk indicators (KRIs)
Answers
C.
To support identification of key risk indicators (KRIs)
D.
To facilitate compliance with external regulatory requirements
Answers
D.
To facilitate compliance with external regulatory requirements
Suggested answer: A

Explanation:

According to the CISM Review Manual, 15th Edition, the primary objective of an information security management system (ISMS) is to align the information security strategy with the business strategy and ensure that information security objectives are consistent with the business objectives1. This helps the organization to achieve its goals and protect its information assets from threats and risks.

Reference=1: CISM Review Manual, 15th Edition, Chapter 1: Information Security Governance, page 11.

asked 01/10/2024
Ed Quinn
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first