CISM · Question #892
Which of the following should review and approve the objectives within an organization's information security framework?
The correct answer is B. Information security steering committee. The information security steering committee is the appropriate governance body to review and approve security framework objectives because it represents cross-functional leadership (business, IT, legal, risk) and has the authority to align security objectives with…
Question
Which of the following should review and approve the objectives within an organization's information security framework?
Options
- ACIO
- BInformation security steering committee
- CCISO
- DInformation security manager
How the community answered
(18 responses)- A6% (1)
- B72% (13)
- C6% (1)
- D17% (3)
Explanation
The information security steering committee is the appropriate governance body to review and approve security framework objectives because it represents cross-functional leadership (business, IT, legal, risk) and has the authority to align security objectives with organizational strategy. The CIO (A) and CISO (C) are executives who typically propose or develop the framework, but approval should come from a broader governance body to ensure buy-in and balanced oversight. The information security manager (D) is an operational role without the authority or cross-organizational perspective needed for strategic approval.
Topics
Community Discussion
No community discussion yet for this question.