CGRC · Question #641
Information Security management is a process of defining the security controls in order to protect information assets. What are the security management responsibilities? Each correct answer…
The correct answer is A. Evaluating business objectives, security risks, user productivity, and functionality requirem ents B. Determining actual goals that are expected to be accomplished from a security program C. Defining steps to ensure that all the responsibilities are accounted for and properly address ed D. Determining objectives, scope, policies, priorities, standards, and strategies. Information security management encompasses a wide range of responsibilities, including evaluating various organizational factors, setting program goals, defining actionable steps, and establishing foundational elements like policies and strategies.
Question
Information Security management is a process of defining the security controls in order to protect information assets. What are the security management responsibilities? Each correct answer represents a complete solution. Choose all that apply. Response:
Options
- AEvaluating business objectives, security risks, user productivity, and functionality requirem ents
- BDetermining actual goals that are expected to be accomplished from a security program
- CDefining steps to ensure that all the responsibilities are accounted for and properly address ed
- DDetermining objectives, scope, policies, priorities, standards, and strategies
How the community answered
(48 responses)- A100% (48)
Why each option
Information security management encompasses a wide range of responsibilities, including evaluating various organizational factors, setting program goals, defining actionable steps, and establishing foundational elements like policies and strategies.
Evaluating business objectives, security risks, user productivity, and functionality requirements are essential for aligning security efforts with organizational goals and ensuring security measures do not unduly hinder operations.
Determining the actual goals expected from a security program provides clear targets and metrics for success, ensuring the program is purpose-driven and measurable.
Defining steps to ensure all responsibilities are accounted for and properly addressed is critical for comprehensive coverage and effective execution of security tasks across the organization.
Determining objectives, scope, policies, priorities, standards, and strategies forms the foundational framework for the entire information security program, guiding all subsequent actions and decisions.
Concept tested: Scope of information security management responsibilities
Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.