exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 217 discussion

Actual exam question from Isaca's CISM
Question #: 217
Topic #: 1
[All CISM Questions]

Which of the following is a PRIMARY responsibility of the information security governance function?

  • A. Administering information security awareness training
  • B. Advising senior management on optimal levels of risk appetite and tolerance
  • C. Defining security strategies to support organizational programs
  • D. Ensuring adequate support for solutions using emerging technologies
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Adabach
1 month ago
Selected Answer: C
Many selected C. but security strategies is certainly a part of information security governance, but it's not the primary responsibility. The governance function also needs to advise on risk appetite and tolerance, ensure compliance with regulations, and oversee the implementation of security strategies.
upvoted 1 times
...
e891cd1
7 months ago
Selected C but B seems to be more appropriate when i read the question. What is the role of information security governance it would be B since governance talks about the entire business not the role of the information security manager..
upvoted 1 times
...
oluchecpoint
9 months ago
Selected Answer: C
The purpose of information security in an organization is to assist the organization in achieving its objectives, and it is the primary goal of an information security strategy. The PRIMARY goal of developing an information security strategy is to: establish security metrics and performance monitoring.
upvoted 2 times
...
oluchecpoint
1 year, 1 month ago
Option B, advising senior management on optimal levels of risk appetite and tolerance, is a primary responsibility of information security governance because it involves setting the tone for how an organization should approach and tolerate risks related to information security, which is a strategic decision at the highest level of management.
upvoted 1 times
oluchecpoint
9 months ago
Changing answer to C
upvoted 1 times
...
...
afc1019
1 year, 2 months ago
Selected Answer: B
One of the most important responsibilities of the information security governance function is to advise senior management on optimal levels of risk appetite and tolerance. This means helping senior management to understand the risks to the organization's information assets and to make informed decisions about how much risk the organization is willing to accept.
upvoted 1 times
...
paul1394
1 year, 2 months ago
Selected Answer: B
According to the ISACA, a primary responsibility of the information security governance function is to advise senior management on optimal levels of risk appetite and tolerance³. This involves providing guidance to senior management on the acceptable levels of risk that the organization is willing to take on in pursuit of its objectives. So, the correct answer to your question would be option B.
upvoted 1 times
...
sham222
1 year, 3 months ago
Selected Answer: B
B-RISK is the primary. Once an org understands it's risk tolerance, then they can decide which security strategies/controls to implement. Until risk is understood, an org won't be able to make choices on which strategies are best for the org. Risk informs budget, areas of focus in the org, what controls/systems to delegate to a 3rd party, whether risk is offset to another entity, etc. Once risk is understood, then and only then can an alignment exist between the biz goals and the org's security program.
upvoted 1 times
...
richck102
1 year, 4 months ago
C. Defining security strategies to support organizational programs
upvoted 1 times
...
dedfef
1 year, 7 months ago
Selected Answer: C
define security strategy
upvoted 3 times
...
Awonenji
1 year, 8 months ago
am in for C
upvoted 1 times
...
DelTrotter
1 year, 10 months ago
Selected Answer: C
Security must be aligned with business.
upvoted 1 times
...
ukwummere1
1 year, 11 months ago
Selected Answer: C
It should be C
upvoted 2 times
...
toffboi
1 year, 11 months ago
Selected Answer: C
I believe the correct answer is C.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago