nerdexam
EC-Council

512-50 · Question #289

Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small…

The correct answer is C. Define formal roles and responsibilities for Information Security. See the full explanation below for the reasoning.

Question

Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years. Which of the following would be the FIRST step when addressing Information Security formally and consistently in this organization?

Options

  • AContract a third party to perform a security risk assessment
  • BDefine formal roles and responsibilities for Internal audit functions
  • CDefine formal roles and responsibilities for Information Security
  • DCreate an executive security steering committee

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    9% (2)
  • C
    73% (16)
  • D
    14% (3)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice