The MOST basic requirement for an information security governance program is to:
The MOST basic requirement for an information security governance program is to:
A . be aligned with the corporate business strategy.
B . be based on a sound risk management approach.
C . provide adequate regulatory compliance.
D . provide best practices for security- initiatives.
Answer: A
Explanation:
To receive senior management support, an information security program should be aligned with the corporate business strategy. Risk management is a requirement of an information security program which should take into consideration the business strategy. Security governance is much broader than just regulatory compliance. Best practice is an operational concern and does not have a direct impact on a governance program.
Latest CISM Dumps Valid Version with 1327 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund