CISSP · Question #173
What is the MOST critical factor to achieve the goals of a security program?
The correct answer is B. Executive management support. Executive management support is the most critical factor for a security program because without organizational authority and resource commitment from leadership, even well-designed security initiatives cannot be effectively implemented or enforced.
Question
Options
- ACapabilities of security resources
- BExecutive management support
- CEffectiveness of security management
- DBudget approved for security resources
How the community answered
(48 responses)- A6% (3)
- B90% (43)
- C2% (1)
- D2% (1)
Why each option
Executive management support is the most critical factor for a security program because without organizational authority and resource commitment from leadership, even well-designed security initiatives cannot be effectively implemented or enforced.
Capabilities of security resources are important but secondary - even highly skilled security staff cannot achieve program goals without the authority and backing that executive support provides.
Executive management support provides the organizational authority, funding prioritization, and policy enforcement power necessary for a security program to succeed. Without top-level sponsorship, security policies lack the mandate needed for compliance across the organization, and resources cannot be allocated effectively. Management support also establishes the security culture and tone from the top that drives employee adherence to security practices.
Effectiveness of security management is a desirable outcome and contributing factor, but it is itself dependent on executive support to function properly, making it a downstream element rather than the most critical root factor.
Budget approval is necessary for resourcing a security program, but budget is granted as a result of executive support, making it a consequence of B rather than the primary driver of program success.
Concept tested: Critical success factors for security program governance
Source: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-2/the-role-of-senior-management-in-information-security
Topics
Community Discussion
No community discussion yet for this question.