Certified Information Security Manager CISM · Free Practice Question Medium
Question 64
What is the PRIMARY objective of information security governance?
- A A) To ensure security strategies align with business objectives and risk management.
- B B) To implement technical controls across the organization's IT infrastructure.
- C C) To conduct regular security training for all employees.
- D D) To achieve compliance with external regulatory requirements.
Reveal correct answer
Correct answer: A
Explanation
Correct Answer: A) To ensure security strategies align with business objectives and risk management. Explanation: Correct (A): Information security governance aims to ensure that the organization's security strategies are aligned with its business objectives and risk management strategies, ensuring that security supports the organization's goals rather than hindering them. Incorrect (B): Implementing technical controls is part of information security management, not the primary objective of governance. Incorrect (C): Conducting security training is an important activity, but it is not the primary objective of governance. Incorrect (D): Achieving compliance is important, but it is a secondary objective that supports the primary goal of aligning security with business objectives.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
