nerdexam
(ISC)2

CGRC · Question #62

Which of the following governance bodies directs and coordinates implementations of the information security program? Response:

The correct answer is D. Chief Information Security Officer. The Chief Information Security Officer (CISO) is the executive responsible for directing and coordinating the implementation of an organization's information security program.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following governance bodies directs and coordinates implementations of the information security program? Response:

Options

  • AInformation Security Steering Committee
  • BSenior Management
  • CBusiness Unit Manager
  • DChief Information Security Officer

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    2% (1)
  • D
    89% (40)

Why each option

The Chief Information Security Officer (CISO) is the executive responsible for directing and coordinating the implementation of an organization's information security program.

AInformation Security Steering Committee

An Information Security Steering Committee provides oversight and strategic guidance but generally does not direct and coordinate implementations at an operational level.

BSenior Management

Senior Management provides overall strategic direction and resources but doesn't typically get involved in the day-to-day directing and coordinating implementations of the security program details.

CBusiness Unit Manager

A Business Unit Manager is responsible for security within their specific unit but not for the overall enterprise-wide direction and coordination of the information security program.

DChief Information Security OfficerCorrect

The Chief Information Security Officer (CISO) is typically a senior-level executive with primary responsibility for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected. This role involves directing and coordinating the security program's implementation across the organization.

Concept tested: Role of Chief Information Security Officer (CISO)

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-100.pdf

Topics

#CISO responsibilities#Information Security Program#Security Governance#Organizational Roles

Community Discussion

No community discussion yet for this question.

Full CGRC Practice