Certified Information Security Manager (CISM)Information Security GovernanceEasy
A newly appointed CISO is tasked with establishing an information security governance framework for a global organization. The CISO recognizes the importance of aligning security initiatives with the overall business objectives and risk appetite. Which of the following is the MOST critical initial step for the CISO to ensure this alignment?
- ADevelop a detailed information security policy document and disseminate it to all employees.
- BIdentify and implement a security information and event management (SIEM) solution.
- CReview the organization's strategic business plan and enterprise risk management framework.
- DConduct a comprehensive technical vulnerability assessment of all IT systems.
Show answer & explanationAnswer & explanation
Correct answer: C. Review the organization's strategic business plan and enterprise risk management framework.
To ensure information security governance aligns with business objectives and risk appetite, the CISO must first understand these foundational elements. Reviewing the strategic business plan and enterprise risk management framework provides this essential context.
Why the other options are wrong
- A. Policy development is a component of security governance, but it should be informed by the strategic plan and risk framework, not precede their review.
- B. Implementing a SIEM is a security control, not an initial step for establishing strategic alignment of governance.
- D. While important, a technical vulnerability assessment is a tactical step and does not establish overall alignment with strategic business objectives.
Strategic Alignment of InfoSec Governance
Ensuring that information security objectives, strategies, and practices support and are integrated with the organization's overall business strategy and risk management framework.
- Security initiatives must support business goals.
- Requires understanding organizational risk appetite.
- Foundation for effective security governance.
Memory trick: Link security to the business's core.