CISM · Question #47
Of the following, who would provide the MOST relevant input when aligning the information security strategy with organizational goals?
The correct answer is C. Information security steering committee. An information security steering committee provides the most relevant input for aligning the information security strategy with overall organizational goals.
Question
Of the following, who would provide the MOST relevant input when aligning the information security strategy with organizational goals?
Options
- AData privacy officer (DPO)
- BChief information security officer (CISO)
- CInformation security steering committee
- DEnterprise risk committee
How the community answered
(43 responses)- A12% (5)
- B5% (2)
- C81% (35)
- D2% (1)
Why each option
An information security steering committee provides the most relevant input for aligning the information security strategy with overall organizational goals.
A Data Privacy Officer (DPO) focuses specifically on privacy regulations and compliance, which is a subset of information security, and would not have the broad organizational view needed for strategic alignment.
The Chief Information Security Officer (CISO) leads the security function, but requires input from across the organization, typically facilitated by a steering committee, to ensure the security strategy aligns with all business objectives.
An information security steering committee typically comprises senior leaders from various business units, IT, and security, ensuring diverse perspectives and comprehensive understanding of organizational goals, risks, and resource allocation. This collective input is crucial for developing a security strategy that is effectively aligned with and supports the broader business objectives.
An enterprise risk committee provides input on overall organizational risks, but an information security steering committee is specifically chartered to align the security strategy with business goals, making its input more directly relevant.
Concept tested: Information security governance
Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/security-baseline/security-governance
Topics
Community Discussion
No community discussion yet for this question.