Certified Information Security Manager (CISM)Information Security ProgramMedium
A CISO is reviewing the information security program's current state and identifies that while technical controls are robust, there is a lack of clear accountability for security decisions and an inconsistent approach to risk management across departments. Which of the following areas of the information security program MOST urgently requires improvement?
- AInformation Security Governance.
- BIncident Response Capabilities.
- CVulnerability Management Process.
- DSecurity Awareness and Training.
Show answer & explanationAnswer & explanation
Correct answer: A. Information Security Governance.
Lack of clear accountability and inconsistent risk management points directly to weaknesses in information security governance. Governance provides the framework for decision-making, roles, responsibilities, and oversight, which are essential for a cohesive and effective security program.
Why the other options are wrong
- B. Incident response relies on clear roles and consistent risk assessment, which are products of good governance. Improving IR without governance addresses symptoms, not the root cause.
- C. Vulnerability management is a technical process. Its effectiveness would be hampered by poor governance that doesn't define clear ownership or risk acceptance criteria.
- D. While important, awareness training addresses human behavior, not the foundational issues of accountability and inconsistent risk management.
Information Security Governance
The system by which an organization directs and controls information security activities, ensuring accountability, transparency, and alignment with business objectives and risk appetite.
- Establishes roles, responsibilities, and decision-making.
- Ensures security aligns with business strategy.
- Provides oversight and accountability for security performance.
Memory trick: Accountability and consistency demand strong 'Governance Guidance'.