CGEIT · Question #8
A large retail chain realizes that while there has not been any loss of da a, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high…
The correct answer is A. Identifying gaps in information asset protection. To make IT security a priority, the first high-level initiative for an IT strategy committee should be to identify existing gaps in information asset protection.
Question
A large retail chain realizes that while there has not been any loss of da a, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high- level initiative for a newly created IT strategy committee in order to support this business goal?
Options
- AIdentifying gaps in information asset protection
- BDefining data archiving and retrieval policies
- CRecruiting and training qualified IT security staff
- DModernizing internal IT security practices
How the community answered
(53 responses)- A83% (44)
- B2% (1)
- C6% (3)
- D9% (5)
Why each option
To make IT security a priority, the first high-level initiative for an IT strategy committee should be to identify existing gaps in information asset protection.
Before any specific improvements or investments can be made, the IT strategy committee must first understand the current state of information asset protection to identify weaknesses, vulnerabilities, and areas lacking adequate controls. This assessment provides the necessary baseline to formulate an effective IT security strategy and prioritize subsequent initiatives.
Defining data archiving and retrieval policies is a specific operational task that comes after understanding the overall security posture and needs.
Recruiting and training staff is an important resource management aspect but should be informed by the identified security gaps and strategic needs.
Modernizing practices is a broad improvement initiative that requires prior knowledge of *what* needs modernization, which comes from gap identification.
Concept tested: Initial step in IT security strategy
Topics
Community Discussion
No community discussion yet for this question.