CISM · Question #16
Which of the following is the MOST important function of an information security steering committee?
The correct answer is D. Obtaining multiple perspectives from the business. The most critical function of an information security steering committee is to gather diverse business perspectives to align security initiatives with organizational goals and risks.
Question
Which of the following is the MOST important function of an information security steering committee?
Options
- AAssigning data classifications to organizational assets
- BDefining security standards for logical access controls
- CDeveloping organizational risk assessment processes
- DObtaining multiple perspectives from the business
How the community answered
(35 responses)- A14% (5)
- B3% (1)
- C9% (3)
- D74% (26)
Why each option
The most critical function of an information security steering committee is to gather diverse business perspectives to align security initiatives with organizational goals and risks.
Assigning data classifications is an operational task often performed by data owners or information security teams based on policies set by governance, not the primary function of a high-level steering committee.
Defining security standards for logical access controls is a detailed policy-level activity, often delegated by the steering committee to technical or policy teams.
Developing organizational risk assessment processes is a function typically performed by the risk management team, with oversight from the steering committee, rather than being the committee's *primary* function.
An information security steering committee, composed of representatives from various business units, ensures that security strategies and investments are aligned with overall business objectives and address diverse departmental needs and risks. This cross-functional perspective is crucial for gaining buy-in, ensuring relevance, and integrating security effectively across the organization.
Concept tested: Information security governance role
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.