nerdexam
(ISC)2

CGRC · Question #469

Information Security management is a process of defining the security controls in order to protect information assets. The first action of a management program to implement information security is…

The correct answer is A. Security organization C. Information classification D. Security education. Key objectives of an information security program include establishing a security organization, classifying information, and providing security education.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Information Security management is a process of defining the security controls in order to protect information assets. The first action of a management program to implement information security is to have a security program in place. What are the objectives of a security program? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • ASecurity organization
  • BSystem classification
  • CInformation classification
  • DSecurity education

How the community answered

(21 responses)
  • A
    95% (20)
  • B
    5% (1)

Why each option

Key objectives of an information security program include establishing a security organization, classifying information, and providing security education.

ASecurity organizationCorrect

Establishing a security organization defines roles, responsibilities, and structures essential for effective security management.

BSystem classification

System classification, while an important activity, is typically a step within an established security program rather than a fundamental objective of the program itself.

CInformation classificationCorrect

Information classification helps determine the sensitivity and value of data, guiding the application of appropriate security controls.

DSecurity educationCorrect

Security education and awareness training is crucial for users to understand and adhere to security policies, reducing human-related risks.

Concept tested: Objectives of an information security program

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-12r1.pdf

Topics

#Security program objectives#Information security management#Security governance#Program establishment

Community Discussion

No community discussion yet for this question.

Full CGRC Practice