Certified Information Security Manager (CISM)Information Security GovernanceMedium
A CISO is establishing an information security governance framework for a newly formed organization. To ensure effective decision-making and clear accountability, which of the following elements is MOST critical to define first?
- AThe budget allocation for the information security department.
- BThe specific information security technologies to be implemented.
- CThe roles, responsibilities, and reporting lines for information security.
- DA detailed list of all applicable legal and regulatory requirements.
Show answer & explanationAnswer & explanation
Correct answer: C. The roles, responsibilities, and reporting lines for information security.
For effective governance, establishing clear roles, responsibilities, and reporting lines is paramount. This defines who makes decisions, who is accountable, and how information security efforts are organized and overseen, forming the foundation for all other governance activities.
Why the other options are wrong
- A. Budget allocation is a resource management aspect that comes after the governance structure and strategic priorities have been defined.
- B. Technology implementation is a tactical decision that follows the establishment of governance and strategic direction.
- D. While knowing legal requirements is crucial, the first step in *establishing governance* is defining the internal structure for managing those requirements and all other security aspects.
InfoSec Governance Framework
A structured system of processes, roles, and responsibilities that directs and controls an organization's information security activities to align with business objectives and manage risks.
- Ensures strategic alignment and risk management.
- Defines accountability and decision-making authority.
- Comprises policies, organizational structures, and processes.
Memory trick: To build governance, first define who does what, and who reports where.