Certified Information Security Manager (CISM)Information Security ProgramMedium

A CISO is reviewing the information security program's current state and identifies that while technical controls are robust, there's a lack of formal oversight and accountability for security processes across different business units. Which of the following actions should the CISO prioritize to address this gap?

  1. AIncreasing the frequency of security awareness training for all employees.
  2. BConducting a penetration test against critical business applications.
  3. CDeveloping and implementing a security governance framework with defined roles, responsibilities, and reporting lines.
  4. DPurchasing and implementing an advanced Security Orchestration, Automation, and Response (SOAR) platform.
Show answer & explanation

Correct answer: C. Developing and implementing a security governance framework with defined roles, responsibilities, and reporting lines.

The problem statement points to a lack of formal oversight and accountability, which are core components of governance. A security governance framework directly addresses these issues by defining who is responsible for what and how security performance is monitored.

Why the other options are wrong

  • A. While important, increased security awareness training does not establish a formal governance structure for accountability.
  • B. Penetration testing evaluates technical vulnerabilities but doesn't solve issues related to organizational accountability and process oversight.
  • D. SOAR platforms automate responses but do not establish the foundational governance needed for oversight and accountability.

Security Governance Framework

A structured approach to defining and implementing security roles, responsibilities, policies, and processes to ensure that security objectives are met and aligned with organizational goals.

  • Establishes accountability.
  • Defines decision-making processes.
  • Integrates security into business operations.

Memory trick: Govern Right to Gain Oversight.

More Information Security Program questions