Certified Information Security Manager (CISM)Information Security ProgramMedium

A CISO is reviewing the information security program's budget allocation for the upcoming fiscal year. The current budget largely focuses on preventative controls, but the organization has recently experienced several sophisticated, nation-state-sponsored attacks that bypassed these controls. The board is now emphasizing resilience and rapid recovery. To align with this new strategic direction, which area of the security program should the CISO advocate for increased investment?

  1. ASecurity awareness training for all employees.
  2. BPerimeter firewalls and intrusion prevention systems (IPS).
  3. CVulnerability management and penetration testing.
  4. DIncident response planning and disaster recovery capabilities.
Show answer & explanation

Correct answer: D. Incident response planning and disaster recovery capabilities.

The board's new emphasis is on 'resilience and rapid recovery' in the face of sophisticated attacks bypassing preventative controls. Increased investment in incident response planning and disaster recovery capabilities directly addresses these goals, focusing on minimizing impact and restoring operations quickly after a breach.

Why the other options are wrong

  • A. Awareness training is a preventative measure for human-centric attacks, not directly addressing resilience and rapid recovery from nation-state-level technical breaches.
  • B. These are preventative controls, which the scenario states were bypassed by sophisticated attacks; further investment here might not address the new resilience focus.
  • C. Vulnerability management and pen testing are largely preventative and detection measures, not directly focused on the 'recovery' aspect emphasized by the board.

Security Program Resilience

The ability of an information security program to anticipate, withstand, recover from, and adapt to adverse conditions, stresses, attacks, or compromises, ensuring business continuity.

  • Moves beyond solely preventative controls.
  • Emphasizes incident response, disaster recovery, and business continuity.
  • Focuses on minimizing impact and accelerating restoration.

Memory trick: When the Wall Breaks, the Team Recovers Fast.

More Information Security Program questions