Isaca
CISM · Question #598
Of the following, who should be PRIMARILY responsible for ensuring the information security policy is executed according to corporate objectives?
The correct answer is C. Senior management. Senior management is primarily responsible for ensuring that the information security policy is executed in alignment with corporate objectives, as they provide direction, oversight, and enforce accountability across the organization.
Submitted by layla.eg· Apr 18, 2026Information Security Governance
Question
Of the following, who should be PRIMARILY responsible for ensuring the information security policy is executed according to corporate objectives?
Options
- ACompliance management
- BIT strategy committee
- CSenior management
- DSecurity steering committee
How the community answered
(39 responses)- A3% (1)
- B3% (1)
- C90% (35)
- D5% (2)
Explanation
Senior management is primarily responsible for ensuring that the information security policy is executed in alignment with corporate objectives, as they provide direction, oversight, and enforce accountability across the organization.
Topics
#Information Security Governance#Senior Management Accountability#Roles and Responsibilities#Policy Execution
Community Discussion
No community discussion yet for this question.