nerdexam
Isaca

CISM · Question #969

To optimize the implementation of information security governance in an organization, an information security manager should:

The correct answer is C. utilize existing governance structures when possible.. Leveraging existing governance structures (e.g., risk committees, steering committees, established reporting lines) is the most effective way to optimize implementation because it embeds security into how the organization already makes decisions and ensures quicker adoption and s

Submitted by kavita_s· Apr 18, 2026Information Security Governance

Question

To optimize the implementation of information security governance in an organization, an information security manager should:

Options

  • Aensure change control processes are in place.
  • Bimplement processes consistent with international standards.
  • Cutilize existing governance structures when possible.
  • Dmake gradual changes to governance to minimize employee resistance.

How the community answered

(55 responses)
  • A
    13% (7)
  • B
    4% (2)
  • C
    78% (43)
  • D
    5% (3)

Explanation

Leveraging existing governance structures (e.g., risk committees, steering committees, established reporting lines) is the most effective way to optimize implementation because it embeds security into how the organization already makes decisions and ensures quicker adoption and sustainability.

Topics

#Information Security Governance#Governance Implementation#Organizational Integration#Optimization

Community Discussion

No community discussion yet for this question.

Full CISM Practice