EC-Council
712-50 · Question #192
A CISO has recently joined an organization with a poorly implemented security program. The desire is to base the security program on a risk management approach. Which of the following is a…
The correct answer is D. A clearly identified executive sponsor who will champion the effort to ensure organizational buy-in. See the full explanation below for the reasoning.
Question
A CISO has recently joined an organization with a poorly implemented security program. The desire is to base the security program on a risk management approach. Which of the following is a foundational requirement in order to initiate this type of program?
Options
- AA security organization that is adequately staffed to apply required mitigation strategies and
- BA clear set of security policies and procedures that are more concept-based than controls-based
- CA complete inventory of Information Technology assets including infrastructure, networks,
- DA clearly identified executive sponsor who will champion the effort to ensure organizational buy-in
How the community answered
(48 responses)- A6% (3)
- B13% (6)
- C4% (2)
- D77% (37)
Community Discussion
No community discussion yet for this question.