Certified Information Security Manager (CISM)Information Security GovernanceMedium

A CISO is establishing an information security governance framework for a newly formed organization. To ensure effective oversight and decision-making, which of the following is the MOST crucial initial step?

  1. AImplementing a risk assessment methodology to prioritize security investments.
  2. BEstablishing clear roles, responsibilities, and accountability for information security.
  3. CDeveloping a comprehensive set of security policies and standards.
  4. DIdentifying and documenting all legal, regulatory, and contractual requirements.
Show answer & explanation

Correct answer: B. Establishing clear roles, responsibilities, and accountability for information security.

Establishing clear roles, responsibilities, and accountability for information security is the most crucial initial step. Without defined ownership and accountability, even well-written policies or identified risks will lack the necessary organizational structure for effective implementation and enforcement.

Why the other options are wrong

  • A. A risk assessment methodology is a tool for decision-making but relies on a governance structure with defined responsibilities to act upon its outputs.
  • C. Policies are important, but without clear roles for their enforcement and adherence, they are less effective.
  • D. Identifying requirements is essential, but someone needs to be responsible for meeting them.

InfoSec Governance Foundation

The fundamental elements required to establish an effective information security governance structure, focusing on organizational clarity and accountability.

  • Defines who is responsible for what.
  • Ensures clear lines of authority and reporting.
  • Critical for effective decision-making and enforcement.

Memory trick: First, assign who's driving and who's navigating; then you can plan the journey.

More Information Security Governance questions