Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium
A Chief Information Security Officer (CISO) is developing a strategy to align the organization's security initiatives with its overall business objectives and risk appetite. The CISO wants to ensure that security investments are prioritized based on their impact on business goals and regulatory requirements. Which aspect of security concepts is the CISO primarily focusing on?
- ASecurity Operations
- BSecurity Awareness Training
- CSecurity Audits
- DSecurity Governance
Show answer & explanationAnswer & explanation
Correct answer: D. Security Governance
Security governance involves establishing a framework of accountability, roles, and processes to align security with business objectives and manage risk. The CISO's actions directly reflect this strategic alignment.
Why the other options are wrong
- A. Security operations focus on the day-to-day management of security systems and incident response, not strategic alignment.
- B. Security awareness training educates employees on security best practices, which is a tactical measure, not a strategic governance activity.
- C. Security audits assess compliance and effectiveness of controls at a specific point in time, which is part of governance but not the overarching focus described.
Security Governance
The framework of accountability, roles, and processes that ensures security initiatives are aligned with business goals, risk appetite, and regulatory requirements.
- Strategic level security management.
- Involves setting policies, standards, and procedures.
- Ensures security investments provide business value.
Memory trick: Governance is the guiding hand, linking security to the business's grand plan.