CISSP · Question #157
Refer to the information below to answer the question. An organization has hired an information security officer to lead their security department. The officer has adequate people resources but is lac
The correct answer is D. risk is lowered to an acceptable level.. The security program can be considered effective when the risk is lowered to an acceptable level. The risk is the possibility or the likelihood of a threat exploiting a vulnerability, and causing a negative impact or a consequence to the organization's assets, operations, or obje
Question
Refer to the information below to answer the question. An organization has hired an information security officer to lead their security department. The officer has adequate people resources but is lacking the other necessary components to have an effective security program. There are numerous initiatives requiring security involvement. The security program can be considered effective when
Options
- Avulnerabilities are proactively identified.
- Baudits are regularly performed and reviewed.
- Cbackups are regularly performed and validated.
- Drisk is lowered to an acceptable level.
How the community answered
(20 responses)- A5% (1)
- B20% (4)
- C10% (2)
- D65% (13)
Explanation
The security program can be considered effective when the risk is lowered to an acceptable level. The risk is the possibility or the likelihood of a threat exploiting a vulnerability, and causing a negative impact or a consequence to the organization's assets, operations, or objectives. The security program is a set of activities and initiatives that aim to protect the organization's information systems and resources from the security threats and risks, and to support the organization's business needs and requirements. The security program can be considered effective when it achieves its goals and objectives, and when it reduces the risk to a level that is acceptable or tolerable by the organization, based on its risk appetite or tolerance. Vulnerabilities are proactively identified, audits are regularly performed and reviewed, and backups are regularly performed and validated are not the criteria to measure the effectiveness of the security program, as they are related to the methods or the processes of the security program, not the outcomes or the results of the security program.
Topics
Community Discussion
No community discussion yet for this question.