Certified Information Security Manager (CISM)Information Security ProgramMedium
A CISO is establishing an information security program for a newly formed startup within the financial technology sector. The startup's primary offering is a mobile payment application. Which of the following should be the CISO's FIRST priority when developing the program?
- ADeveloping a detailed incident response plan with a dedicated CERT team.
- BEstablishing a strong governance framework aligned with business objectives.
- CImplementing advanced threat detection and response systems.
- DConducting a comprehensive penetration test of the mobile application.
Show answer & explanationAnswer & explanation
Correct answer: B. Establishing a strong governance framework aligned with business objectives.
Establishing a strong governance framework is the foundational step for any information security program. It ensures that security efforts are aligned with business objectives and regulatory requirements from the outset, providing direction and accountability for all subsequent security activities.
Why the other options are wrong
- A. An incident response plan is critical, but it is a component of a mature security program that needs a governance foundation to define its scope and authority.
- C. Implementing advanced technical controls is important but should follow a defined strategy and governance structure.
- D. Penetration testing is a valuable assessment tool, but it is a tactical activity that should be part of a broader, governed security program.
Information Security Governance
The system by which an organization directs and controls information security activities, ensuring they align with business goals, manage risks, and comply with regulations.
- Provides strategic direction for security.
- Establishes roles, responsibilities, and accountability.
- Ensures security aligns with overall enterprise governance.
Memory trick: Building a house needs a blueprint first, not just tools.