nerdexam
(ISC)2

CSSLP · Question #84

Which of the following governance bodies directs and coordinates implementations of the information security program?

The correct answer is A. Chief Information Security Officer. The Chief Information Security Officer (CISO) is the executive responsible for directing and coordinating the implementation of the information security program within an organization.

Secure Software Lifecycle Management

Question

Which of the following governance bodies directs and coordinates implementations of the information security program?

Options

  • AChief Information Security Officer
  • BInformation Security Steering Committee
  • CBusiness Unit Manager
  • DSenior Management

How the community answered

(42 responses)
  • A
    90% (38)
  • B
    2% (1)
  • C
    2% (1)
  • D
    5% (2)

Why each option

The Chief Information Security Officer (CISO) is the executive responsible for directing and coordinating the implementation of the information security program within an organization.

AChief Information Security OfficerCorrect

The Chief Information Security Officer (CISO) is a senior-level executive who holds the primary responsibility for developing, directing, and coordinating the overall information security program for an organization. This role involves establishing security policies, managing security operations, and ensuring the program aligns with business objectives and regulatory requirements.

BInformation Security Steering Committee

An Information Security Steering Committee provides governance, oversight, and strategic guidance for the security program, but the CISO is the individual role responsible for its direct coordination and implementation.

CBusiness Unit Manager

A Business Unit Manager is responsible for managing security within their specific business unit or area of responsibility, not for directing the organization-wide information security program.

DSenior Management

Senior Management provides overall executive support, resources, and ultimate approval for the information security program, but the CISO is the designated leader responsible for its day-to-day and strategic implementation.

Concept tested: Information security governance roles-CISO

Topics

#Information Security Governance#CISO Roles and Responsibilities#Security Program Management

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice