CISM · Question #819
Which of the following is the BEST approach for reporting information security noncompliance to senior management?
The correct answer is D. Explain the potential impact of noncompliance.. Senior management is primarily concerned with business impact. Explaining the potential impact of noncompliance translates security issues into business risk, enabling informed decision- making, whereas root causes or remediation costs are secondary at the executive level.
Question
Which of the following is the BEST approach for reporting information security noncompliance to senior management?
Options
- AExplain the root cause of the noncompliance.
- BExplain the cost of remediation for noncompliance.
- CExplain scenarios of noncompliance at competing organizations.
- DExplain the potential impact of noncompliance.
How the community answered
(51 responses)- A6% (3)
- B2% (1)
- C10% (5)
- D82% (42)
Explanation
Senior management is primarily concerned with business impact. Explaining the potential impact of noncompliance translates security issues into business risk, enabling informed decision- making, whereas root causes or remediation costs are secondary at the executive level.
Topics
Community Discussion
No community discussion yet for this question.