CISM · Question #140
When establishing an information security governance framework, it is MOST important for an information security manager to understand:
The correct answer is B. the corporate culture.. When establishing an information security governance framework, it is most important for an information security manager to understand the corporate culture, as this dictates how security policies and practices will be adopted and enforced.
Question
When establishing an information security governance framework, it is MOST important for an information security manager to understand:
Options
- Ainformation security best practices.
- Bthe corporate culture.
- Crisk management techniques.
- Dthe threat environment.
How the community answered
(41 responses)- A2% (1)
- B90% (37)
- C2% (1)
- D5% (2)
Why each option
When establishing an information security governance framework, it is most important for an information security manager to understand the corporate culture, as this dictates how security policies and practices will be adopted and enforced.
Information security best practices are technical guidelines that should be incorporated *into* the framework, but understanding the culture determines how they are practically applied.
Understanding the corporate culture is paramount because it influences how security policies are perceived, adopted, and adhered to by employees, and how security initiatives are supported by leadership. A framework that doesn't align with or account for the existing culture risks being ineffective or even rejected, regardless of its technical soundness.
Risk management techniques are tools used *within* the framework, but the cultural context affects their implementation and effectiveness.
The threat environment informs the *content* of the security framework, but culture determines its successful integration and operation within the organization.
Concept tested: Information security governance and corporate culture
Topics
Community Discussion
No community discussion yet for this question.