712-50 · Question #477
Which of the following is the MOST important to share with an Information Security Steering Committee:
The correct answer is B. Review audit and compliance reports. Reviewing audit and compliance reports (B) is the steering committee's core governance function - it gives leadership the data needed to make strategic, risk-informed decisions about the security program's effectiveness and direction. Option A (mixed membership) describes how…
Question
Which of the following is the MOST important to share with an Information Security Steering Committee:
Options
- AInclude a mix of members from different departments and staff levels
- BReview audit and compliance reports
- CEnsure that security policies and procedures have been vetted and approved
- DBe briefed about new trends and products at each meeting by a vendor
How the community answered
(39 responses)- A3% (1)
- B77% (30)
- C8% (3)
- D13% (5)
Explanation
Reviewing audit and compliance reports (B) is the steering committee's core governance function - it gives leadership the data needed to make strategic, risk-informed decisions about the security program's effectiveness and direction. Option A (mixed membership) describes how to compose the committee, not what it shares or does at meetings, making it a structural consideration rather than a primary activity. Option C (vetting security policies) is an important committee responsibility, but it's subordinate to the oversight function - policy approval follows from understanding what the audit/compliance data reveals. Option D (vendor briefings) introduces a conflict of interest and is not an appropriate steering committee function; that work belongs in evaluation teams, not governance bodies.
Memory tip: Think of a steering committee like a board of directors - their job is oversight through data, not operations. "Review reports" = governance; everything else listed is either setup, execution, or a distraction.
Topics
Community Discussion
No community discussion yet for this question.