Certified Information Security Manager CISM · Free Practice Question Medium

Question 64

What is the PRIMARY objective of information security governance?
  • A A) To ensure security strategies align with business objectives and risk management.
  • B B) To implement technical controls across the organization's IT infrastructure.
  • C C) To conduct regular security training for all employees.
  • D D) To achieve compliance with external regulatory requirements.
Reveal correct answer

Correct answer: A

Explanation

Correct Answer: A) To ensure security strategies align with business objectives and risk management. Explanation: Correct (A): Information security governance aims to ensure that the organization's security strategies are aligned with its business objectives and risk management strategies, ensuring that security supports the organization's goals rather than hindering them. Incorrect (B): Implementing technical controls is part of information security management, not the primary objective of governance. Incorrect (C): Conducting security training is an important activity, but it is not the primary objective of governance. Incorrect (D): Achieving compliance is important, but it is a secondary objective that supports the primary goal of aligning security with business objectives.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need