nerdexam
(ISC)2

CSSLP · Question #207

Information Security management is a process of defining the security controls in order to protect information assets. The first action of a management program to implement information security is…

The correct answer is A. Security education B. Security organization D. Information classification. The core objectives of an information security program include educating personnel on security practices, establishing a clear security organization structure, and classifying information assets to apply appropriate protection.

Secure Software Concepts

Question

Information Security management is a process of defining the security controls in order to protect information assets. The first action of a management program to implement information security is to have a security program in place. What are the objectives of a security program? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ASecurity education
  • BSecurity organization
  • CSystem classification
  • DInformation classification

How the community answered

(19 responses)
  • A
    89% (17)
  • C
    11% (2)

Why each option

The core objectives of an information security program include educating personnel on security practices, establishing a clear security organization structure, and classifying information assets to apply appropriate protection.

ASecurity educationCorrect

Security education is a vital objective of a security program, as it ensures that all users understand their roles and responsibilities in maintaining security and are aware of potential threats and best practices.

BSecurity organizationCorrect

Establishing a clear security organization with defined roles, responsibilities, and reporting structures is a fundamental objective for effective management and implementation of security controls.

CSystem classification

While systems support information, "System classification" itself is not a primary, distinct objective of an information security program in the same way that classifying the information within those systems is. The focus is on the information assets.

DInformation classificationCorrect

Information classification is a key objective, as it involves categorizing data based on its sensitivity and criticality, which then guides the application of appropriate security controls and protection mechanisms.

Concept tested: Objectives of an information security program

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-gdpr-security

Topics

#Information Security Management#Security Program Objectives#Security Awareness#Information Classification

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice