nerdexam
EC-Council

512-50 · Question #213

A CISO has recently joined an organization with a poorly implemented security program. The desire is to base the security program on a risk management approach. Which of the following is a…

The correct answer is D. A clearly identified executive sponsor who will champion the effort to ensure organizational buy-in. See the full explanation below for the reasoning.

Question

A CISO has recently joined an organization with a poorly implemented security program. The desire is to base the security program on a risk management approach. Which of the following is a foundational requirement in order to initiate this type of program?

Options

  • AA security organization that is adequately staffed to apply required mitigation strategies and
  • BA clear set of security policies and procedures that are more concept-based than controls-based
  • CA complete inventory of Information Technology assets including infrastructure, networks,
  • DA clearly identified executive sponsor who will champion the effort to ensure organizational buy-in

How the community answered

(20 responses)
  • A
    15% (3)
  • B
    5% (1)
  • C
    5% (1)
  • D
    75% (15)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice