nerdexam
(ISC)2

SSCP · Question #462

Which approach to a security program ensures people responsible for protecting the company's assets are DRIVING the program?

The correct answer is B. The top-down approach. A security program should use a top-down approach, meaning that the initiation, support, and direction come from top management; work their way through middle management; and then reach staff members. In contrast, a bottom-up approach refers to a situation in which staff members

Submitted by tarun92· Apr 18, 2026Security Concepts and Practices

Question

Which approach to a security program ensures people responsible for protecting the company's assets are DRIVING the program?

Options

  • AThe Delphi approach
  • BThe top-down approach
  • CThe bottom-up approach
  • DThe technology approach

How the community answered

(24 responses)
  • B
    92% (22)
  • C
    4% (1)
  • D
    4% (1)

Explanation

A security program should use a top-down approach, meaning that the initiation, support, and direction come from top management; work their way through middle management; and then reach staff members. In contrast, a bottom-up approach refers to a situation in which staff members (usually IT ) try to develop a security program without getting proper management support and direction. A bottom- up approach is commonly less effective, not broad enough to address all security risks, and A top-down approach makes sure the people actually responsible for protecting the company's assets (senior management) are driving the program. The following are incorrect answers: The Delphi approach is incorrect as this is for a brainstorming technique. The bottom-up approach is also incorrect as this approach would be if the IT department tried to develop a security program without proper support from upper management. The technology approach is also incorrect as it does not fit into the category of best answer.

Topics

#Security Program Management#Organizational Security#Top-down approach

Community Discussion

No community discussion yet for this question.

Full SSCP Practice