CISM · Question #122
Which of the following is the MOST useful input for an information security manager when updating the organization's security policy?
The correct answer is B. Risk appetite. The organization's risk appetite is the most crucial input for updating security policies, as it defines the acceptable level of risk the business is willing to tolerate.
Question
Which of the following is the MOST useful input for an information security manager when updating the organization’s security policy?
Options
- ASecurity team capabilities
- BRisk appetite
- CVulnerability scan
- DIndustry best practices
How the community answered
(27 responses)- A11% (3)
- B78% (21)
- C7% (2)
- D4% (1)
Why each option
The organization's risk appetite is the most crucial input for updating security policies, as it defines the acceptable level of risk the business is willing to tolerate.
Security team capabilities influence *how* policies are implemented and enforced, but not the fundamental "what" of the policy itself.
Security policies should primarily reflect the organization's defined risk appetite, guiding what security measures are necessary and how rigorously they must be enforced to achieve an acceptable level of risk. Without understanding the risk appetite, policies may be either overly restrictive or insufficiently protective, leading to misaligned security efforts.
Vulnerability scan results identify specific technical weaknesses, which might inform technical controls, but the overarching policy framework needs to be guided by risk appetite.
Industry best practices provide guidance and benchmarks, but policies must be tailored to the organization's specific risk tolerance, which might differ from general best practices.
Concept tested: Security policy development inputs
Topics
Community Discussion
No community discussion yet for this question.