SSCP · Question #462
Which approach to a security program ensures people responsible for protecting the company's assets are DRIVING the program?
The correct answer is B. The top-down approach. A security program should use a top-down approach, meaning that the initiation, support, and direction come from top management; work their way through middle management; and then reach staff members. In contrast, a bottom-up approach refers to a situation in which staff members
Question
Which approach to a security program ensures people responsible for protecting the company's assets are DRIVING the program?
Options
- AThe Delphi approach
- BThe top-down approach
- CThe bottom-up approach
- DThe technology approach
How the community answered
(24 responses)- B92% (22)
- C4% (1)
- D4% (1)
Explanation
A security program should use a top-down approach, meaning that the initiation, support, and direction come from top management; work their way through middle management; and then reach staff members. In contrast, a bottom-up approach refers to a situation in which staff members (usually IT ) try to develop a security program without getting proper management support and direction. A bottom- up approach is commonly less effective, not broad enough to address all security risks, and A top-down approach makes sure the people actually responsible for protecting the company's assets (senior management) are driving the program. The following are incorrect answers: The Delphi approach is incorrect as this is for a brainstorming technique. The bottom-up approach is also incorrect as this approach would be if the IT department tried to develop a security program without proper support from upper management. The technology approach is also incorrect as it does not fit into the category of best answer.
Topics
Community Discussion
No community discussion yet for this question.