CISM · Question #810
Which of the following would be the GREATEST concern if an information security manager defines a security approach according to industry best practices?
The correct answer is A. Alignment with organizational objectives. Defining a security approach solely based on industry best practices may result in misalignment with the organization’s specific business objectives and risk appetite. CISM emphasizes that security must be business-driven; best practices should be adapted, not adopted blindly.
Question
Which of the following would be the GREATEST concern if an information security manager defines a security approach according to industry best practices?
Options
- AAlignment with organizational objectives
- BAlignment with IT strategy
- CExcessive security control cost
- DManual control framework
How the community answered
(28 responses)- A75% (21)
- B7% (2)
- C4% (1)
- D14% (4)
Explanation
Defining a security approach solely based on industry best practices may result in misalignment with the organization’s specific business objectives and risk appetite. CISM emphasizes that security must be business-driven; best practices should be adapted, not adopted blindly.
Topics
Community Discussion
No community discussion yet for this question.