712-50 · Question #260
Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only slows things down…
The correct answer is D. All of the above. Option D is correct because building a security program that has buy-in requires input from all stakeholder groups - executives set the tone and allocate resources, end users reveal real-world friction points, and peers (fellow security/IT professionals) contribute technical…
Question
Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only slows things down and limits the performance of the "real workers." Which group of people should be consulted when developing your security program?
Options
- APeers
- BEnd Users
- CExecutive Management
- DAll of the above
How the community answered
(46 responses)- A7% (3)
- B2% (1)
- C13% (6)
- D78% (36)
Explanation
Option D is correct because building a security program that has buy-in requires input from all stakeholder groups - executives set the tone and allocate resources, end users reveal real-world friction points, and peers (fellow security/IT professionals) contribute technical expertise. When cultural resistance exists (as described in the scenario), excluding any group risks the program being ignored, underfunded, or actively undermined. Each group alone is insufficient: peers (A) only provide technical perspective without organizational authority; end users (B) can highlight usability concerns but lack strategic influence; executive management (C) can mandate compliance but without user input may create policies that don't reflect operational reality.
Memory tip: Think "PEE-U" - Peers, End users, Executives, and U (you) all shape culture. Security programs fail when any voice is left out, especially when resistance already exists.
Topics
Community Discussion
No community discussion yet for this question.