Certified Information Security Manager (CISM)Information Security ProgramMedium
A CISO is reviewing the information security program's current state and identifies that while technical controls are robust, there's a lack of formal oversight and accountability for security processes across different business units. Which of the following actions should the CISO prioritize to address this gap?
- AIncreasing the frequency of security awareness training for all employees.
- BConducting a penetration test against critical business applications.
- CDeveloping and implementing a security governance framework with defined roles, responsibilities, and reporting lines.
- DPurchasing and implementing an advanced Security Orchestration, Automation, and Response (SOAR) platform.
Show answer & explanationAnswer & explanation
Correct answer: C. Developing and implementing a security governance framework with defined roles, responsibilities, and reporting lines.
The problem statement points to a lack of formal oversight and accountability, which are core components of governance. A security governance framework directly addresses these issues by defining who is responsible for what and how security performance is monitored.
Why the other options are wrong
- A. While important, increased security awareness training does not establish a formal governance structure for accountability.
- B. Penetration testing evaluates technical vulnerabilities but doesn't solve issues related to organizational accountability and process oversight.
- D. SOAR platforms automate responses but do not establish the foundational governance needed for oversight and accountability.
Security Governance Framework
A structured approach to defining and implementing security roles, responsibilities, policies, and processes to ensure that security objectives are met and aligned with organizational goals.
- Establishes accountability.
- Defines decision-making processes.
- Integrates security into business operations.
Memory trick: Govern Right to Gain Oversight.