nerdexam
Isaca

CISM · Question #598

Of the following, who should be PRIMARILY responsible for ensuring the information security policy is executed according to corporate objectives?

The correct answer is C. Senior management. Senior management is primarily responsible for ensuring that the information security policy is executed in alignment with corporate objectives, as they provide direction, oversight, and enforce accountability across the organization.

Submitted by layla.eg· Apr 18, 2026Information Security Governance

Question

Of the following, who should be PRIMARILY responsible for ensuring the information security policy is executed according to corporate objectives?

Options

  • ACompliance management
  • BIT strategy committee
  • CSenior management
  • DSecurity steering committee

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    90% (35)
  • D
    5% (2)

Explanation

Senior management is primarily responsible for ensuring that the information security policy is executed in alignment with corporate objectives, as they provide direction, oversight, and enforce accountability across the organization.

Topics

#Information Security Governance#Senior Management Accountability#Roles and Responsibilities#Policy Execution

Community Discussion

No community discussion yet for this question.

Full CISM Practice