Certified Information Security Manager CISM · Free Practice Question Easy
Question 72
- A To permit the organization to control all information security–related activities
- B To give management visibility into and control of information security matters
- C To permit the CISO to control the business and its priorities
- D To control all security-related activities in the organization
Reveal correct answer
Correct answer: B
Explanation
Correct Answer:
To give management visibility into and control of information security matters is correct. The purpose of security governance is to give management (specifically, executive management) visibility into and control of all things related to information security.
Incorrect Answers:
To control all security-related activities in the organization and To permit the organization to control all information security–related activities are plausible but not the best answers.
To permit the CISO to control the business and its priorities is incorrect because the purpose of governance is to give business management control of information security, not the CISO.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
