Board approval is crucial for demonstrating the organization's commitment to cybersecurity and ensuring that the policy aligns with the overall business strategy.
A policy that has not been approved by the board may not be fully implemented or supported by senior management, which can weaken its effectiveness.
ll of the deficiencies mentioned are concerning, but the one that should be of MOST concern is:
D. The policy has not been approved by the organization's board.
Approval by the organization's board is crucial because it signifies high-level acknowledgment and commitment to the cybersecurity policy. Without board approval, the policy may lack the necessary authority, resources, and enforcement mechanisms to be effectively implemented throughout the organization. This deficiency indicates a fundamental gap in governance and oversight, which can undermine the organization's ability to effectively address cybersecurity risks.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Sara98
2 months, 2 weeks agoJecalyn
8 months agoJoloms
9 months, 2 weeks ago