CISM · Question #223
Which of the following would BEST ensure that security risk assessment is integrated into the life cycle of major IT projects?
The correct answer is B. Having the information security manager participate on the project steering committees. The best way to ensure that security risk assessment is integrated into the life cycle of major IT projects is by having the information security manager participate on the project steering committees. This ensures that security risks are consistently considered and addressed dur
Question
Which of the following would BEST ensure that security risk assessment is integrated into the life cycle of major IT projects?
Options
- AIntegrating the risk assessment into the internal audit program
- BHaving the information security manager participate on the project steering committees
- CApplying global security standards to the IT projects
- DTraining project managers on risk assessment
How the community answered
(23 responses)- A4% (1)
- B70% (16)
- C13% (3)
- D13% (3)
Explanation
The best way to ensure that security risk assessment is integrated into the life cycle of major IT projects is by having the information security manager participate on the project steering committees. This ensures that security risks are consistently considered and addressed during key project phases and decision-making. While training project managers and applying global standards are helpful, direct involvement by the information security manager in steering committees allows for ongoing oversight and integration of security risk assessments throughout the project's life cycle.
Topics
Community Discussion
No community discussion yet for this question.