Certified Information Security Manager CISM · Free Practice Question Easy
Question 115
When developing an information security program, what should be the primary criterion for success?
- A A reduction in the number of security breaches
- B Ensuring compliance with security regulations
- C The number of security controls implemented
- D The program’s contribution to achieving business objectives
Reveal correct answer
Correct answer: D
Explanation
The Correct Answer: The program’s contribution to achieving business objectives: The ultimate measure of success for an information security program is how well it contributes to achieving the organization’s strategic goals. Security efforts must be aligned with business needs, and the program should enhance the organization’s ability to meet its objectives. The Incorrect Answers: The number of security controls implemented: While controls are important, the quantity of controls alone does not indicate success. The focus should be on how those controls contribute to the organization’s goals. A reduction in the number of security breaches: Reducing breaches is important, but it is not the primary measure of success. The security program should support business continuity and resilience, beyond just minimizing incidents. Ensuring compliance with security regulations: Compliance is necessary but should not be the sole criterion for success. A successful security program should support business objectives and enhance the organization's ability to operate securely and effectively.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
