CISM · Question #719
Which of the following should be established FIRST when implementing an information security governance framework?
The correct answer is A. Security policies. Security policies must be established first because they define the organization's security objectives, principles, and requirements - essentially the "rules of the game" that everything else is built upon. Without documented policies, there is no authoritative foundation to guid
Question
Which of the following should be established FIRST when implementing an information security governance framework?
Options
- ASecurity policies
- BSecurity incident management team
- CSecurity architecture
- DSecurity awareness training program
How the community answered
(63 responses)- A87% (55)
- B5% (3)
- C2% (1)
- D6% (4)
Explanation
Security policies must be established first because they define the organization's security objectives, principles, and requirements - essentially the "rules of the game" that everything else is built upon. Without documented policies, there is no authoritative foundation to guide what architecture to design, who to train, or what incidents to respond to.
- B (Incident management team) is wrong because the team needs policies to know what constitutes an incident and how to respond - you can't operationalize a function without its governing rules.
- C (Security architecture) is wrong because architecture decisions must align with policy requirements; building architecture first risks designing a system that contradicts later-defined organizational intent.
- D (Security awareness training) is wrong because training must teach employees what the policies require - if no policies exist, there is nothing substantive to train on.
Memory tip: Think of governance as building a house - policies are the blueprint. You don't hire a crew (incident team), frame walls (architecture), or train workers (awareness) before the blueprint exists.
Topics
Community Discussion
No community discussion yet for this question.