Certified Information Security Manager (CISM)Information Security GovernanceEasy
A CISO is tasked with ensuring information security initiatives are aligned with the organization's overall business objectives and strategy. Which of the following is the MOST effective approach to achieve this alignment?
- AImplementing a robust security awareness training program for all employees.
- BProcuring the latest security technologies to enhance defense capabilities.
- CEstablishing a formal information security governance framework integrated with enterprise governance.
- DConducting regular penetration tests and vulnerability assessments.
Show answer & explanationAnswer & explanation
Correct answer: C. Establishing a formal information security governance framework integrated with enterprise governance.
Establishing a formal information security governance framework integrated with enterprise governance ensures that security objectives are directly linked to business goals, providing strategic alignment and oversight. This proactive approach ensures security supports the business rather than being a separate, reactive function.
Why the other options are wrong
- A. Security awareness is important for culture but does not inherently align security initiatives with business objectives at a strategic level.
- B. Procuring technology is an operational task and does not guarantee strategic alignment with business objectives.
- D. Penetration tests and vulnerability assessments are tactical security measures, not strategic alignment mechanisms.
Information Security Governance
The system by which an organization directs and controls information security, ensuring that security efforts are aligned with business objectives and risks are managed appropriately.
- Ensures security aligns with business goals.
- Provides strategic direction and oversight.
- Manages information security risks.
Memory trick: Aligning security with business is like a secure path to profit.