Certified Information Security Manager (CISM)Information Security ProgramMedium

A CISO is tasked with implementing a new information security program. To ensure the program continuously adapts to evolving threats and organizational changes, which principle should be MOST heavily emphasized during its design and ongoing management?

  1. AImplementing a continuous improvement model with regular reviews and adjustments.
  2. BMaximizing the initial investment in security technologies to achieve a high baseline.
  3. CAdopting a 'set it and forget it' approach once controls are deemed effective.
  4. DPrioritizing compliance with a single regulatory standard above all other considerations.
Show answer & explanation

Correct answer: A. Implementing a continuous improvement model with regular reviews and adjustments.

Information security is not a static state. A continuous improvement model (e.g., Plan-Do-Check-Act) ensures the program remains relevant, effective, and resilient against new threats and changes in the business environment, making it crucial for long-term success.

Why the other options are wrong

  • B. While a strong baseline is good, security is dynamic; initial investment alone won't ensure long-term adaptation.
  • C. A 'set it and forget it' approach is antithetical to effective security management and would quickly lead to obsolescence and increased risk.
  • D. Compliance is important, but over-prioritizing a single standard can lead to neglecting other risks or a lack of adaptability when the standard changes.

Continuous Security Improvement

An ongoing process of evaluating, refining, and enhancing an information security program to adapt to new threats, technologies, and business requirements, often following a Plan-Do-Check-Act cycle.

  • Ensures long-term program effectiveness.
  • Adapts to dynamic threat landscapes.
  • Involves regular monitoring, review, and adjustment.

Memory trick: Security's mantra: 'Continuously improve, never static'.

More Information Security Program questions