exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 517 discussion

Actual exam question from Isaca's CISM
Question #: 517
Topic #: 1
[All CISM Questions]

How does an organization's information security steering committee facilitate the achievement of information security program objectives?

  • A. Monitoring information security resources
  • B. Making decisions on security priorities
  • C. Enforcing regulatory and policy compliance
  • D. Evaluating information security metrics
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 5 months ago
Selected Answer: B
B it is boys!
upvoted 5 times
...
1899f17
Most Recent 1 month, 2 weeks ago
B. Making decisions on security priorities
upvoted 1 times
...
Ka2021ka
3 months, 4 weeks ago
Selected Answer: B
D. Evaluating information security metrics is indeed a task that the steering committee might engage in to gauge the effectiveness of the security program, but the core facilitation occurs through setting priorities and directing the strategic focus of the program.
upvoted 1 times
...
AlexJacobson
5 months, 3 weeks ago
Selected Answer: B
Infosec manager evaluates the metrics and presents them to the steering committee, who then (based on that) decides on direction and priorities.
upvoted 1 times
...
oluchecpoint
10 months, 1 week ago
Selected Answer: B
B. Making decisions on security priorities An organization's information security steering committee facilitates the achievement of information security program objectives primarily by making decisions on security priorities. The steering committee typically consists of key stakeholders from various departments within the organization, including IT, legal, compliance, and business units. Its role is to provide strategic guidance and oversight for the organization's information security efforts. By making decisions on security priorities, the committee helps ensure that the information security program aligns with the organization's overall goals and objectives. This includes determining where resources should be allocated, which security initiatives should take precedence, and how to address emerging threats and vulnerabilities. Their decisions can have a significant impact on the direction and effectiveness of the information security program.
upvoted 1 times
...
AaronS1990
10 months, 2 weeks ago
Selected Answer: B
I would say it uses D (metrics) in order to achieve B. B is actually the helpful part so I'd go with that.
upvoted 1 times
...
Goseu
12 months ago
Selected Answer: B
Steering committees are all about steering to the right directions when needed. Therefore answer is clearly B
upvoted 1 times
...
richck102
1 year ago
B. Making decisions on security priorities
upvoted 2 times
...
karanvp
1 year ago
Selected Answer: D
Measurement can help to make decisions which all help to achieve. Hence Metrics is my choice.
upvoted 1 times
...
wello
1 year, 1 month ago
Selected Answer: D
D. Evaluating information security metrics by evaluating the metrics, they can check the status, make decisions on policies among other things to make sure the org can achieve the objectives.
upvoted 2 times
...
Souvik124
1 year, 4 months ago
An information security steering committee can facilitate the achievement of information security program objectives by making decisions on security priorities. The committee is responsible for setting the direction and vision of the organization's information security program and establishing priorities based on risk assessments and business needs. They can allocate resources and make decisions on what security measures should be implemented, such as technology, policies, and procedures, to achieve the security objectives. The committee may also review and evaluate the effectiveness of the security measures implemented and make necessary adjustments to ensure that the organization's information security program remains effective.
upvoted 3 times
...
aokisan
1 year, 6 months ago
Selected Answer: D
to evaluate achievement is needed the metrics.
upvoted 1 times
...
Ziggybooboo
1 year, 7 months ago
Agreed on B
upvoted 4 times
...
k4d4v4r
1 year, 9 months ago
Selected Answer: B
Why not B?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago