Certified Information Security Manager (CISM)Information Security GovernanceHard

During a strategic planning session, the board expresses concern about the organization's ability to adapt its information security program to rapidly evolving cyber threats and new regulatory mandates. Which of the following information security governance principles should the CISO emphasize to address this concern MOST effectively?

  1. ATransparency, by providing regular and comprehensive reports on security posture.
  2. BIntegration, by embedding security into all business processes and decision-making.
  3. CAgility, by ensuring the security program can rapidly respond to changes in the threat landscape and regulatory environment.
  4. DAccountability, by clearly defining roles and responsibilities for security tasks.
Show answer & explanation

Correct answer: C. Agility, by ensuring the security program can rapidly respond to changes in the threat landscape and regulatory environment.

The board's concern is about adaptability to evolving threats and mandates. Agility directly addresses this by emphasizing the security program's ability to respond quickly and effectively to changes, ensuring its continued relevance and efficacy.

Why the other options are wrong

  • A. Transparency is important for reporting, but it focuses on communication, not the inherent ability of the program to *change and adapt* itself.
  • B. Integration ensures security is built-in, but the core of the board's concern is the *rate and ease of adaptation* to external changes, which is agility.
  • D. Accountability is a fundamental governance principle, but it doesn't directly address the *adaptability* aspect of the board's concern.

Agility in InfoSec Governance

The principle that an information security governance framework and program should be flexible and responsive, capable of rapidly adapting to changes in the threat landscape, technology, business objectives, and regulatory requirements.

  • Enables continuous relevance and effectiveness of security.
  • Crucial in dynamic environments with evolving cyber threats.
  • Supports proactive risk management and compliance.

Memory trick: For evolving threats, your security must be swift and agile.

More Information Security Governance questions