exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 79 discussion

Actual exam question from Isaca's CISM
Question #: 79
Topic #: 1
[All CISM Questions]

Which of the following is the MOST important consideration when selecting members for an information security steering committee?

  • A. Information security expertise
  • B. Tenure in the organization
  • C. Business expertise
  • D. Cross-functional composition
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dark_3k03r
Highly Voted 1 year, 3 months ago
Selected Answer: D
The Correct Answer is D because an information Security Steering Committee is composed of the following members: The chief information security officer (CISO) The chief information officer (CIO) The chief operating officer (COO) The chief financial officer (CFO) The general counsel Representatives from key business units Representatives from key functional areas (i.e. human resources, IT, and legal) and the only answer that hs this is D. Rationale: A. Is limited to only one group B. Doesn't have enough diversity C. Tenure doesn't say anything about diversity D. This is the correct answer since cross-functional composition is the practice of assembling a team with members from different functional areas or departments within an organization.
upvoted 8 times
...
1899f17
Most Recent 1 month, 1 week ago
C. Business expertise
upvoted 1 times
...
oluchecpoint
5 months, 1 week ago
Selected Answer: A
Without individuals with strong information security expertise on the committee, it may struggle to make informed decisions and effectively protect the organization's sensitive information and systems.
upvoted 1 times
...
Viperhunter
7 months, 3 weeks ago
Selected Answer: C
While information security expertise (Option A) is valuable, having members with business expertise is crucial for the success of an information security steering committee. Information security is not just a technical concern; it is also a business risk that needs to be aligned with overall organizational goals and strategies. Committee members with a strong understanding of the organization's business operations, priorities, and objectives can better integrate information security into the broader business context. Tenure in the organization (Option B) may bring institutional knowledge but does not necessarily guarantee the necessary expertise or alignment with business goals. Cross-functional composition (Option D) is important as it ensures diverse perspectives, but business expertise is still a critical factor for effective decision-making related to information security within the organization.
upvoted 1 times
...
oluchecpoint
10 months, 2 weeks ago
A. Information security expertise While all the options listed are valuable qualities for committee members, information security expertise is the most critical factor when it comes to ensuring that the committee can effectively address and make decisions about security-related issues. Information security is a specialized field that requires a deep understanding of the evolving threat landscape, best practices, compliance requirements, and risk management strategies. Without individuals with strong information security expertise on the committee, it may struggle to make informed decisions and effectively protect the organization's sensitive information and systems. That said, a well-rounded committee should ideally also include members with business expertise (to align security initiatives with organizational goals), cross-functional composition (to represent various parts of the organization), and tenure in the organization (to provide historical context). However, these qualities should complement the primary criterion of information security expertise.
upvoted 1 times
...
Akam
11 months, 3 weeks ago
For me it's A. If you don't have knowledgeable information security personnel, then it doesn't matter who will be included in this commitee.
upvoted 1 times
...
Nillanash
1 year ago
D-Cross functional composition will enable the steering committee to better represent the organization.
upvoted 2 times
...
richck102
1 year, 1 month ago
D. Cross-functional composition
upvoted 1 times
...
jaiz
1 year, 4 months ago
Selected Answer: D
D. Various stakeholders should involve as committee member
upvoted 1 times
...
Antonivs
1 year, 5 months ago
Selected Answer: D
D, people from different areas is key
upvoted 2 times
...
Broesweelies
1 year, 6 months ago
Selected Answer: A
A. Information security expertise is the MOST important consideration when selecting members for an information security steering committee. The primary role of the information security steering committee is to provide oversight and guidance to ensure that the organization's information security goals are met. To do this effectively, the members of the committee should have a strong understanding of information security concepts, risks, and best practices. B, C, and D are also important considerations, as tenure in the organization can bring valuable institutional knowledge and experience, business expertise ensures that security decisions align with the organization's overall goals, and cross-functional composition ensures that different perspectives and concerns are considered. But the foremost important is the knowledge of information security.
upvoted 3 times
AlexJacobson
5 months, 3 weeks ago
No, it is not. Representation of various departments and business functions is the key when building a strong steering committee.
upvoted 1 times
...
...
MSKid
1 year, 8 months ago
Selected Answer: D
The committee needs to come from different organization staff from multiple business levels
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago