nerdexam
(ISC)2

CGRC · Question #641

Information Security management is a process of defining the security controls in order to protect information assets. What are the security management responsibilities? Each correct answer…

The correct answer is A. Evaluating business objectives, security risks, user productivity, and functionality requirem ents B. Determining actual goals that are expected to be accomplished from a security program C. Defining steps to ensure that all the responsibilities are accounted for and properly address ed D. Determining objectives, scope, policies, priorities, standards, and strategies. Information security management encompasses a wide range of responsibilities, including evaluating various organizational factors, setting program goals, defining actionable steps, and establishing foundational elements like policies and strategies.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Information Security management is a process of defining the security controls in order to protect information assets. What are the security management responsibilities? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • AEvaluating business objectives, security risks, user productivity, and functionality requirem ents
  • BDetermining actual goals that are expected to be accomplished from a security program
  • CDefining steps to ensure that all the responsibilities are accounted for and properly address ed
  • DDetermining objectives, scope, policies, priorities, standards, and strategies

How the community answered

(48 responses)
  • A
    100% (48)

Why each option

Information security management encompasses a wide range of responsibilities, including evaluating various organizational factors, setting program goals, defining actionable steps, and establishing foundational elements like policies and strategies.

AEvaluating business objectives, security risks, user productivity, and functionality requirem entsCorrect

Evaluating business objectives, security risks, user productivity, and functionality requirements are essential for aligning security efforts with organizational goals and ensuring security measures do not unduly hinder operations.

BDetermining actual goals that are expected to be accomplished from a security programCorrect

Determining the actual goals expected from a security program provides clear targets and metrics for success, ensuring the program is purpose-driven and measurable.

CDefining steps to ensure that all the responsibilities are accounted for and properly address edCorrect

Defining steps to ensure all responsibilities are accounted for and properly addressed is critical for comprehensive coverage and effective execution of security tasks across the organization.

DDetermining objectives, scope, policies, priorities, standards, and strategiesCorrect

Determining objectives, scope, policies, priorities, standards, and strategies forms the foundational framework for the entire information security program, guiding all subsequent actions and decisions.

Concept tested: Scope of information security management responsibilities

Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-39.pdf

Topics

#Security Management#Governance#Risk Management#Program Planning

Community Discussion

No community discussion yet for this question.

Full CGRC Practice