CISM · Question #31
Which of the following BEST indicates that information security governance and corporate governance are integrated?
The correct answer is D. The information security steering committee is composed of business leaders. The integration of information security and corporate governance is best indicated when the security steering committee includes business leaders, ensuring security decisions align with and support overall business objectives.
Question
Which of the following BEST indicates that information security governance and corporate governance are integrated?
Options
- AThe information security team is aware of business goals.
- BA cost-benefit analysis is conducted on all information security initiatives.
- CThe board is regularly informed of information security key performance indicators (KPIs).
- DThe information security steering committee is composed of business leaders.
How the community answered
(36 responses)- A8% (3)
- B6% (2)
- C22% (8)
- D64% (23)
Why each option
The integration of information security and corporate governance is best indicated when the security steering committee includes business leaders, ensuring security decisions align with and support overall business objectives.
While awareness of business goals by the security team is good, it doesn't necessarily mean security is integrated into corporate governance at the highest levels.
Conducting a cost-benefit analysis is a sound financial practice, but it's a tactical step rather than an indicator of strategic, integrated governance.
Informing the board of KPIs is a reporting mechanism, indicating oversight, but doesn't, by itself, demonstrate deep integration into the decision-making and strategic planning processes.
When an information security steering committee is composed of business leaders from various departments, it signifies that information security is viewed as a strategic business concern, not just an IT function. This integration ensures that security initiatives are aligned with overarching corporate goals, risks are assessed from a business perspective, and security decisions receive top-level support and resources.
Concept tested: Information security governance integration
Topics
Community Discussion
No community discussion yet for this question.