CISSP · Question #154
Refer to the information below to answer the question. An organization has hired an information security officer to lead their security department. The officer has adequate people resources but is lac
The correct answer is A. Formal acceptance of the security strategy. The most important priority for the information security officer is to obtain the formal acceptance of the security strategy. The security strategy is a document that defines the vision, mission, goals, and objectives of the security program, and that aligns the security activiti
Question
Refer to the information below to answer the question. An organization has hired an information security officer to lead their security department. The officer has adequate people resources but is lacking the other necessary components to have an effective security program. There are numerous initiatives requiring security involvement. Which of the following is considered the MOST important priority for the information security officer?
Options
- AFormal acceptance of the security strategy
- BDisciplinary actions taken against unethical behavior
- CDevelopment of an awareness program for new employees
- DAudit of all organization system configurations for faults
How the community answered
(35 responses)- A54% (19)
- B6% (2)
- C14% (5)
- D26% (9)
Explanation
The most important priority for the information security officer is to obtain the formal acceptance of the security strategy. The security strategy is a document that defines the vision, mission, goals, and objectives of the security program, and that aligns the security activities and initiatives with the business needs and requirements. The formal acceptance of the security strategy means that the security strategy is approved and supported by the senior management and the key stakeholders of the organization, and that it is communicated and understood by the employees and the users. The formal acceptance of the security strategy can help to ensure the success and the effectiveness of the security program, as it can provide the authority, the resources, the guidance, and the accountability for the security officer and the security department. Disciplinary actions taken against unethical behavior, development of an awareness program for new employees, and audit of all organization system configurations for faults are not the most important priorities for the information security officer, as they are related to the enforcement, the education, or the evaluation of the security policies and procedures, not the definition or the approval of the security strategy.
Topics
Community Discussion
No community discussion yet for this question.