Certified Information Security Manager CISM · Free Practice Question Easy

Question 72

What is the purpose of information security governance?
  • A To permit the organization to control all information security–related activities
  • B To give management visibility into and control of information security matters
  • C To permit the CISO to control the business and its priorities
  • D To control all security-related activities in the organization
Reveal correct answer

Correct answer: B

Explanation

Correct Answer:

To give management visibility into and control of information security matters is correct. The purpose of security governance is to give management (specifically, executive management) visibility into and control of all things related to information security.

Incorrect Answers:

To control all security-related activities in the organization and To permit the organization to control all information security–related activities are plausible but not the best answers.

To permit the CISO to control the business and its priorities is incorrect because the purpose of governance is to give business management control of information security, not the CISO.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need