CISM · Question #622
What is the PRIMARY role of the information security program?
The correct answer is B. To provide guidance in managing organizational security risk. The overarching purpose of an information security program is to provide a framework and guidance for managing organizational security risk in alignment with business objectives. All other activities - approving requirements (A), educating stakeholders (C), and conducting risk…
Question
What is the PRIMARY role of the information security program?
Options
- ATo approve information security requirements related to the business
- BTo provide guidance in managing organizational security risk
- CTo educate stakeholders regarding information security requirements
- DTo perform periodic risk assessments and business impact analyses (BIAs)
How the community answered
(34 responses)- A6% (2)
- B88% (30)
- C3% (1)
- D3% (1)
Explanation
The overarching purpose of an information security program is to provide a framework and guidance for managing organizational security risk in alignment with business objectives. All other activities - approving requirements (A), educating stakeholders (C), and conducting risk assessments and BIAs (D) - are supporting functions that serve this primary goal. The program exists to ensure the organization understands and manages its security risks in a structured, consistent way.
Topics
Community Discussion
No community discussion yet for this question.