CISM · Question #104
Which of the following is MOST likely to improve an organization's security culture?
The correct answer is A. Involving stakeholders in security planning. Involving stakeholders in security planning actively engages them, fosters a sense of ownership, and significantly improves the organization's security culture.
Question
Which of the following is MOST likely to improve an organization's security culture?
Options
- AInvolving stakeholders in security planning
- BEnforcing penalties for security incidents
- CCommunicating security incidents within the industry
- DIncentivizing managers based on security metrics
How the community answered
(22 responses)- A82% (18)
- C5% (1)
- D14% (3)
Why each option
Involving stakeholders in security planning actively engages them, fosters a sense of ownership, and significantly improves the organization's security culture.
Involving stakeholders in security planning fosters a sense of ownership and shared responsibility, making security a collective effort rather than solely an IT department concern. This engagement ensures that security measures are practical, understood, and supported across various departments, leading to a more robust and pervasive security culture.
Enforcing penalties, while necessary for compliance, can foster resentment and fear, which are detrimental to building a positive and proactive security culture.
Communicating security incidents within the industry can raise external awareness but does not directly translate to improved internal security culture among employees.
Incentivizing managers based on security metrics can drive performance but might also lead to "gaming" metrics rather than genuinely improving the security culture if not carefully implemented.
Concept tested: Cultivating security culture
Topics
Community Discussion
No community discussion yet for this question.