nerdexam
(ISC)2

CGRC · Question #181

Which of the following is a subset discipline of Corporate Governance focused on information security systems and their performance and risk management? Response:

The correct answer is B. ISG. Information Security Governance (ISG) is a specialized discipline within Corporate Governance that specifically addresses the management of information security systems, their performance, and associated risks.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following is a subset discipline of Corporate Governance focused on information security systems and their performance and risk management? Response:

Options

  • ALanham Act
  • BISG
  • CClinger-Cohen Act
  • DComputer Misuse Act

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    93% (25)
  • C
    4% (1)

Why each option

Information Security Governance (ISG) is a specialized discipline within Corporate Governance that specifically addresses the management of information security systems, their performance, and associated risks.

ALanham Act

The Lanham Act is a federal statute in the United States that governs trademarks, service marks, and unfair competition, not information security governance.

BISGCorrect

Information Security Governance (ISG) is precisely defined as a subset of corporate governance that focuses on ensuring the confidentiality, integrity, and availability of information assets, including managing security risks and monitoring performance of security systems. It provides the framework for an organization's security program, aligning it with business goals.

CClinger-Cohen Act

The Clinger-Cohen Act (CCA) is U.S. federal legislation focused on improving the way the federal government acquires, uses, and manages information technology, but it is not a general term for information security governance.

DComputer Misuse Act

The Computer Misuse Act is a piece of criminal legislation in the United Kingdom that prohibits unauthorized access to computer material, but it is a law, not a governance discipline.

Concept tested: Information Security Governance definition

Source: https://csrc.nist.gov/glossary/term/information-security-governance

Topics

#Information Security Governance#Corporate Governance#Risk Management#Performance Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice