nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #738

What is the primary purpose of an information security governance framework?

The correct answer is A. To provide strategic direction for information security. An information security governance framework exists primarily to provide strategic direction - aligning security objectives with business goals, defining roles and responsibilities, and guiding decision-making at the executive level. While governance frameworks do result in…

Security Principles

Question

What is the primary purpose of an information security governance framework?

Options

  • ATo provide strategic direction for information security
  • BTo establish policies and procedures
  • CTo enforce disciplinary actions for security violations
  • DTo ensure compliance with regulations

How the community answered

(30 responses)
  • A
    87% (26)
  • B
    7% (2)
  • C
    3% (1)
  • D
    3% (1)

Explanation

An information security governance framework exists primarily to provide strategic direction - aligning security objectives with business goals, defining roles and responsibilities, and guiding decision-making at the executive level. While governance frameworks do result in policies (B), compliance requirements (D), and disciplinary measures (C), those are outputs or by-products of governance, not its primary purpose. Governance is the 'why and where we're going'; management is the 'how.' The ISACA definition reinforces this: governance ensures that security strategies are set and monitored at the board/leadership level.

Topics

#Information Security Governance#Strategic Planning#Security Frameworks#Cybersecurity Management

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice