exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 285 discussion

Actual exam question from Isaca's CISM
Question #: 285
Topic #: 1
[All CISM Questions]

Which of the following is the PRIMARY responsibility of an information security governance committee?

  • A. Reviewing the information security risk register
  • B. Approving changes to the information security strategy
  • C. Discussing upcoming information security projects
  • D. Reviewing monthly information security metrics
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
oluchecpoint
10 months ago
B. Approving changes to the information security strategy The PRIMARY responsibility of an information security governance committee is to approve changes to the information security strategy. This committee is typically responsible for setting the direction and priorities for an organization's information security efforts, and approving changes to the strategy ensures that security measures align with the organization's goals and risk tolerance. While other activities mentioned, such as reviewing the information security risk register, discussing upcoming projects, and reviewing metrics, are important functions of an information security governance committee, they often support or contribute to the development and execution of the security strategy, but approving the strategy itself is a central and primary responsibility.
upvoted 1 times
...
Hugo1717
10 months, 2 weeks ago
Selected Answer: B
The correct answer is B. Approving changes to the information security strategy. Explanation: Among the options provided, approving changes to the information security strategy is the primary responsibility of an information security governance committee. Here's why this option is the primary responsibility: B. Approving changes to the information security strategy: The information security governance committee is responsible for setting the direction and priorities of information security efforts within an organization. Approving changes to the information security strategy ensures that the organization's security goals align with its overall objectives.
upvoted 1 times
...
richck102
1 year ago
B. Approving changes to the information security strategy
upvoted 1 times
...
jaiz
1 year, 3 months ago
Selected Answer: B
Yes, approving changes to the information security strategy is generally considered to be the primary responsibility of an information security governance committee. The information security governance committee is responsible for overseeing and guiding the overall information security program, including the development and maintenance of the information security strategy.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...