Certified Information Security Manager CISM · Free Practice Question Medium
Question 102
In the context of developing a new information security strategy, what should be the Chief Information Security Officer's (CISO's) primary focus to ensure alignment with organizational goals?
- A Reviewing the latest cybersecurity technologies and trends
- B Conducting a comprehensive risk assessment
- C Drafting a detailed budget for the security program
- D Engaging with stakeholders from various departments
Reveal correct answer
Correct answer: B
Explanation
The Correct Answer: Conducting a comprehensive risk assessment: Conducting a comprehensive risk assessment is paramount as it provides the foundational understanding of the organization's security posture. This process helps identify potential threats, vulnerabilities, and the potential impact on organizational assets, thus aligning security objectives with business goals. This ensures that the security strategy is not only robust but also targeted towards protecting the most critical assets in line with the organization's risk appetite and tolerance. The Incorrect Answers: Engaging with stakeholders from various departments: While engaging with stakeholders is crucial for gathering insights and ensuring that security strategies support various business functions, it should follow the initial risk assessment. Understanding risks forms the basis for meaningful stakeholder engagement by allowing discussions to be focused on mitigating identified risks that could affect departmental operations and objectives. Reviewing the latest cybersecurity technologies and trends: This option focuses on technical solutions rather than a strategic approach. While staying updated with technologies is important, it is not the primary step when aligning a security strategy with organizational goals. Technology should support a strategy informed by a comprehensive understanding of risks. Drafting a detailed budget for the security program: Budgeting is an important step in implementing a security strategy, but drafting a budget without first understanding the risks would be premature. Financial resources should be allocated based on identified risks and priorities to ensure effective mitigation and alignment with overall organizational goals.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
