CAS-003 · Question #570
A Chief Information Security Officer (CISO) is creating a security committee involving multiple business units of the corporation. Which of the following is the BEST justification to ensure…
The correct answer is C. Without business unit collaboration, risks introduced by one unit that affect another unit may. Security risks do not respect organizational boundaries. A vulnerability, misconfigured system, or compromised account in one business unit can directly propagate to - or create cascading risk for - other units that share networks, data, or integrations. Without a collaborative…
Question
A Chief Information Security Officer (CISO) is creating a security committee involving multiple business units of the corporation. Which of the following is the BEST justification to ensure collaboration across business units?
Options
- AA risk to one business unit is a risk avoided by all business units, and liberal BYOD policies
- BA single point of coordination is required to ensure cybersecurity issues are addressed in
- CWithout business unit collaboration, risks introduced by one unit that affect another unit may
- DThe CISO is uniquely positioned to control the flow of vulnerability information between
How the community answered
(47 responses)- A9% (4)
- B2% (1)
- C85% (40)
- D4% (2)
Explanation
Security risks do not respect organizational boundaries. A vulnerability, misconfigured system, or compromised account in one business unit can directly propagate to - or create cascading risk for - other units that share networks, data, or integrations. Without a collaborative security committee, these cross-unit risks may never be surfaced, communicated, or mitigated before they cause broader damage. This is the strongest justification for cross-business-unit collaboration. Option A introduces BYOD policy as a justification, which is unrelated to why a committee is needed. Option B describes the operational function of a committee but not why collaboration specifically is required. Option D frames the CISO as a gatekeeper rather than a collaborator, which works against the goal.
Topics
Community Discussion
No community discussion yet for this question.