Certified Information Security Manager (CISM)Information Security GovernanceMedium
A newly appointed CISO is tasked with establishing an information security governance framework for an organization that has historically lacked formal security oversight. The organization operates in a highly regulated industry. Which of the following should be the CISO's MOST immediate priority?
- APurchase and deploy a Security Information and Event Management (SIEM) system for centralized logging.
- BDevelop and implement an incident response plan to handle potential security breaches.
- CEstablish an information security steering committee composed of key business and IT stakeholders.
- DConduct a comprehensive technical vulnerability assessment and penetration test of all critical systems.
Show answer & explanationAnswer & explanation
Correct answer: C. Establish an information security steering committee composed of key business and IT stakeholders.
Establishing an information security steering committee is paramount for formalizing governance. This committee provides strategic direction, ensures business alignment, allocates resources, and gains executive buy-in, which are all foundational for building an effective security program, especially in a regulated industry.
Why the other options are wrong
- A. A SIEM is a technical tool for monitoring, but it doesn't establish the governance structure needed to guide the overall security program.
- B. An incident response plan is critical, but its effectiveness depends on underlying governance and resource allocation, which a steering committee provides.
- D. Technical assessments are important, but they are tactical steps that should be guided by a governance framework.
InfoSec Steering Committee
A formal body composed of diverse stakeholders (business, IT, security) that provides strategic guidance, oversight, and decision-making for the information security program.
- Ensures business alignment of security initiatives.
- Facilitates resource allocation and prioritization.
- Promotes communication and accountability across the organization.
Memory trick: First, gather the leaders to chart the security course.