exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 23 discussion

Actual exam question from Isaca's CISM
Question #: 23
Topic #: 1
[All CISM Questions]

Executive leadership has decided to engage a consulting firm to develop and implement a comprehensive security framework for the organization to allow senior management to remain focused on business priorities. Which of the following poses the GREATEST challenge to the successful implementation of the new security governance framework?

  • A. Executive leadership becomes involved in decisions about information security governance.
  • B. Executive leadership views information security governance primarily as a concern of the information security management team
  • C. Information security staff has little or no experience with the practice of information security governance.
  • D. Information security management does not fully accept the responsibility for information security governance.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mark169
2 days, 12 hours ago
Selected Answer: B
Executive leaderschip decides to let senior maangeent focus on runnig the business. Security is part of the business so B.
upvoted 1 times
...
6b41e93
3 weeks, 5 days ago
Selected Answer: D
• Information Security Management Does Not Fully Accept the Responsibility for Information Security Governance (D): If the information security management team does not fully accept responsibility for information security governance, it can create a significant barrier to the successful implementation and ongoing management of the security framework. A lack of ownership and commitment from those directly responsible for overseeing information security can lead to poor implementation, inadequate enforcement of policies, and a general failure to integrate security governance effectively within the organization
upvoted 1 times
...
e891cd1
11 months, 1 week ago
Executive management are ultimately responsible for the security governance of the business and they are also needed to support and sponsor the program. So if their understanding is lacking that will be the greatest risk..
upvoted 1 times
...
Viperhunter
1 year, 1 month ago
Selected Answer: B
For a security governance framework to be successful, it is crucial that executive leadership understands and actively supports information security governance. If leadership views it primarily as the concern of the information security management team alone, it may lead to a lack of commitment, insufficient resources, and a failure to integrate security into the overall business strategy. A successful security governance framework requires top-down commitment and involvement from executive leadership to ensure that security is aligned with business priorities. While the other options (executive leadership becoming involved, information security staff lacking experience, and information security management not fully accepting responsibility) are also potential challenges, the lack of engagement and understanding from executive leadership can have broad-reaching impacts on the success of the security governance framework.
upvoted 1 times
...
King21
1 year, 3 months ago
I would say answer is D. Responsibility cannot be outsourced.
upvoted 1 times
AlexJacobson
11 months, 3 weeks ago
That's accountability your thinking of. Responsibility CAN be delegated, but accountability cannot.
upvoted 2 times
...
...
Ridenar
1 year, 5 months ago
this might answer it. Another key element that shouldbe understood is that although the security manager is the facilitator of the program, the ultimate responsibility or ownership for protecting information is at the executiveleadership and board of directors levels. The security charter gives the security leaderauthority to design and operate the program, but accountability is shared between thesecurity leader and the executive leadership team and board of directors.
upvoted 1 times
...
richck102
1 year, 7 months ago
B. Executive leadership views information security governance primarily as a concern of the information security management team
upvoted 3 times
...
dedfef
1 year, 9 months ago
Selected Answer: B
to down approach
upvoted 2 times
...
CarlLimps
1 year, 11 months ago
Selected Answer: B
B for sure. Want to make sure leadership sees this as a business risk, not ONLY infosec issue.
upvoted 3 times
...
Antonivs
1 year, 11 months ago
hard question this one
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago