CISM · Question #99
Which of the following is the MOST important goal of an information security program?
The correct answer is B. Reducing risk factors. The primary goal of an information security program is to reduce risk factors to an acceptable level by protecting information assets from threats and vulnerabilities.
Question
Which of the following is the MOST important goal of an information security program?
Options
- AOptimizing resources
- BReducing risk factors
- CManaging controls
- DEnhancing business decision making
How the community answered
(30 responses)- A3% (1)
- B87% (26)
- C7% (2)
- D3% (1)
Why each option
The primary goal of an information security program is to reduce risk factors to an acceptable level by protecting information assets from threats and vulnerabilities.
Optimizing resources is a goal of efficient management but secondary to the core objective of protecting information assets through risk reduction.
The most important goal of an information security program is to reduce risk factors by implementing controls that mitigate threats and vulnerabilities to an acceptable level. This focus ensures the protection of an organization's information assets and supports business objectives by minimizing potential harm from security incidents. All other security activities ultimately serve this overarching objective of risk reduction.
Managing controls is a means to achieve security, not the ultimate goal itself; controls are implemented to reduce risk.
Enhancing business decision making can be a benefit of a well-managed security program, but the core purpose is the protection of assets and operations, primarily through risk reduction.
Concept tested: Information security program objectives
Topics
Community Discussion
No community discussion yet for this question.