CISM · Question #68
Which of the following should be the PRIMARY objective for creating a culture of security within an organization?
The correct answer is B. To reduce risk to acceptable levels. The primary objective for creating a culture of security within an organization is to reduce overall risk to acceptable levels.
Question
Which of the following should be the PRIMARY objective for creating a culture of security within an organization?
Options
- ATo obtain resources for information security initiatives
- BTo reduce risk to acceptable levels
- CTo prioritize security within the organization
- DTo demonstrate control effectiveness to senior management
How the community answered
(34 responses)- A3% (1)
- B94% (32)
- D3% (1)
Why each option
The primary objective for creating a culture of security within an organization is to reduce overall risk to acceptable levels.
Obtaining resources for information security initiatives is a means to achieve security goals, not the primary objective of a security culture itself.
The primary objective for creating a culture of security is to reduce overall organizational risk to acceptable levels by integrating security awareness and practices into the daily routines and mindset of all employees. This collective responsibility and vigilance help prevent incidents stemming from human error or malicious intent, thereby mitigating potential threats and vulnerabilities effectively.
To prioritize security within the organization is an outcome of a strong security culture, but the ultimate goal of that prioritization is the reduction of risk.
Demonstrating control effectiveness to senior management is a management function that might be aided by a strong security culture, but it's not the culture's primary objective.
Concept tested: Security culture objectives
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-50.pdf
Topics
Community Discussion
No community discussion yet for this question.