CISM · Question #712
Which of the following would BEST assist an information security manager in gaining strategic support from executive management?
The correct answer is D. A risk analysis specific to the organization. A risk analysis specific to the organization directly ties security concerns to business impact in terms executives understand - financial exposure, operational risk, and regulatory consequences - making it the most persuasive tool for gaining strategic buy-in. Why the…
Question
Which of the following would BEST assist an information security manager in gaining strategic support from executive management?
Options
- AAn information security maturity model
- BAn annual report of security incidents within the organization
- CResearch on trends in global information security breaches
- DA risk analysis specific to the organization
How the community answered
(42 responses)- A2% (1)
- B7% (3)
- C12% (5)
- D79% (33)
Explanation
A risk analysis specific to the organization directly ties security concerns to business impact in terms executives understand - financial exposure, operational risk, and regulatory consequences - making it the most persuasive tool for gaining strategic buy-in.
Why the distractors fall short:
- A (Maturity model): Useful for benchmarking and internal roadmaps, but too abstract for executives who need to see their business risk, not a framework score.
- B (Annual incident report): Historical data on past incidents is reactive and doesn't communicate forward-looking strategic risk or business consequences clearly enough to drive executive decisions.
- C (Global breach trends): Industry-wide research lacks organizational context - executives are more moved by "here's what we stand to lose" than "here's what happened to others."
Memory tip: Think of it this way - executives speak the language of business risk, not security metrics. The word "specific to the organization" in option D is the key signal; anything generic or historical won't resonate as strongly as a tailored risk analysis that maps security gaps directly to business outcomes.
Topics
Community Discussion
No community discussion yet for this question.