CISM · Question #14
An information security team must obtain approval from the information security steering committee to implement a key control. Which of the following is the MOST important input to assist the…
The correct answer is D. Business case. When seeking approval for a key security control, the information security steering committee requires a business case to understand the control's justification and value.
Question
An information security team must obtain approval from the information security steering committee to implement a key control. Which of the following is the MOST important input to assist the committee in making this decision?
Options
- AIT strategy
- BSecurity architecture
- CRisk assessment
- DBusiness case
How the community answered
(64 responses)- A6% (4)
- B3% (2)
- C11% (7)
- D80% (51)
Why each option
When seeking approval for a key security control, the information security steering committee requires a business case to understand the control's justification and value.
IT strategy provides overall direction but does not detail the specific justification, costs, and benefits of a particular key control implementation.
Security architecture describes the design and components of the security system, but it does not articulate the business reasons or financial implications for adopting a specific control.
A risk assessment identifies and prioritizes risks, but it is typically an *input* to building the business case, rather than the complete justification needed for a committee's approval.
A business case outlines the problem, proposed solution (the key control), its benefits (risk reduction, compliance), costs, and return on investment. This comprehensive view allows the steering committee to evaluate the strategic and financial implications of implementing the control, making it the most important input for their decision.
Concept tested: Justifying security investments to leadership
Topics
Community Discussion
No community discussion yet for this question.