Which of the following is the MOST effective approach for determining whether an organization's information security program supports the information security strategy?
A.
Ensure resources meet information security program needs
B.
Audit the information security program to identify deficiencies
C.
Identify gaps impacting information security strategy
D.
Develop key performance indicators (KPIs) of information security
What you have to keep in mind for this test is what is the best option so that everyone can track what is going on. For this question that would be KPI. KPI's are user friendly charts and graphs that a child could understand what is going on. This would be a great tool in order to show the stakeholders what is going on.
Identifying gaps impacting the information security strategy involves assessing the alignment between the information security program and the overarching security strategy. This approach helps identify any deficiencies, misalignments, or areas where the information security program falls short in supporting the strategic objectives. By understanding these gaps, the organization can take targeted actions to improve the alignment between the program and the strategy.
While options like ensuring resources meet information security program needs (option A), auditing the information security program to identify deficiencies (option B), and developing key performance indicators (KPIs) of information security (option D) are important activities, identifying and addressing gaps in alignment with the information security strategy is a proactive step toward improving overall effectiveness.
D
Developing key performance indicators (KPIs) for information security allows for a continuous, data-driven assessment of how well the information security program aligns with and supports the information security strategy. This approach helps in identifying areas of improvement, optimizing resource allocation, and ensuring that security efforts are effective in achieving strategic objectives.
These are so frustrating. There’s not a definitive answer. The discussions are great but there are so many discussions on these test questions that it makes me question what’s right.
D is correct. C is incorrect because a security strategy is far too vague to identify any gaps. Its meant to be vague. KPIs are metrics and always BEST option.
D is the right answer. The question is asking for the MOST effective approach.
While a gap analysis will help find out what they need to align the ISP to the strategy better. KPIs will help them show if the ISP is actually working as the strategy has outlined it.
yes, should be C.
By identifying these gaps, the organization can take steps to address them and ensure that its information security program is aligned with its information security strategy.
"C" is the correct one: Identify gaps impacting information security strategy
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
greeklover84
1 month, 4 weeks agoSHERLOCKAWS
11 months, 1 week agoPOWNED
12 months agoViperhunter
12 months agoAaronS1990
1 year, 2 months agooluchecpoint
1 year, 2 months agokaibutsu
1 year, 2 months agoPatt70
1 year, 2 months agoAzurefox79
1 year, 3 months agoDavoA
1 year, 4 months agoJKatta2023
1 year, 4 months agokaranvp
1 year, 5 months agorichck102
1 year, 6 months agoDravidian
1 year, 7 months agovavofa5697
1 year, 9 months agoCarlLimps
1 year, 9 months agoideu
1 year, 10 months ago