Certified Information Security Manager (CISM)Information Security GovernanceHard
An organization is struggling with inconsistent application of information security policies across different departments, leading to varied risk exposures. The CISO needs to address this issue across the enterprise. Which of the following governance actions is MOST effective in establishing a consistent security posture?
- AImplement a centralized security policy management system with automated enforcement capabilities.
- BEstablish a cross-functional information security steering committee to oversee policy implementation.
- CConduct individual departmental risk assessments to tailor policies to specific needs.
- DMandate quarterly security awareness training for all employees, emphasizing policy adherence.
Show answer & explanationAnswer & explanation
Correct answer: B. Establish a cross-functional information security steering committee to oversee policy implementation.
Inconsistent policy application across departments is a governance issue. A cross-functional steering committee provides the necessary authority, oversight, and collaboration to ensure consistent interpretation, implementation, and enforcement of policies across the entire enterprise.
Why the other options are wrong
- A. While a centralized system can help, without proper governance (like a steering committee) to define, approve, and oversee policy, the system itself won't solve inconsistencies in interpretation or buy-in.
- C. Tailoring policies too much can exacerbate inconsistency. While departmental input is valuable, the goal is consistent application (with appropriate flexibility, but under central governance), not independent policy development.
- D. Training is important for awareness, but it doesn't solve the underlying governance issue of inconsistent policy application and enforcement across diverse departments.
InfoSec Steering Committee
A formal group comprising representatives from various business units and IT, responsible for providing strategic direction, oversight, and coordination for information security initiatives and policy implementation.
- Ensures alignment with business objectives.
- Facilitates consistent policy interpretation and enforcement.
- Promotes enterprise-wide buy-in and accountability for security.
Memory trick: To harmonize security across departments, let a committee steer the course.