nerdexam
Isaca

CISM · Question #5

A new information security manager finds that the organization tends to use short-term solutions to address problems. Resource allocation and spending are not effectively tracked, and there is no…

The correct answer is D. Create an information security steering committee. To reverse a bottom-up security approach and address systemic issues like short-term solutions and poor tracking, the information security manager should first establish an information security steering committee.

Submitted by klara.se· Apr 18, 2026Information Security Governance

Question

A new information security manager finds that the organization tends to use short-term solutions to address problems. Resource allocation and spending are not effectively tracked, and there is no assurance that compliance requirements are being met. What should be done FIRST to reverse this bottom-up approach to security?

Options

  • AImplement an information security awareness training program.
  • BConduct a threat analysis.
  • CEstablish an audit committee.
  • DCreate an information security steering committee.

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    9% (3)
  • C
    6% (2)
  • D
    71% (25)

Why each option

To reverse a bottom-up security approach and address systemic issues like short-term solutions and poor tracking, the information security manager should first establish an information security steering committee.

AImplement an information security awareness training program.

Implementing awareness training is important but addresses user behavior rather than the systemic lack of strategic oversight and resource allocation.

BConduct a threat analysis.

Conducting a threat analysis is an operational task that provides input for risk management but does not establish the necessary top-down governance structure.

CEstablish an audit committee.

Establishing an audit committee primarily focuses on oversight of financial reporting and internal controls, not directly on the strategic direction and resource allocation of information security.

DCreate an information security steering committee.Correct

An information security steering committee, composed of senior management from various departments, provides strategic direction, ensures alignment with business goals, and enables top-down enforcement of security initiatives, which is crucial for moving away from a reactive, bottom-up approach. This committee establishes governance, allocates resources effectively, and oversees compliance, addressing all the identified problems structurally.

Concept tested: Information security governance establishment

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf

Topics

#Information Security Governance#Steering Committee#Strategic Direction#Program Establishment

Community Discussion

No community discussion yet for this question.

Full CISM Practice