D. The information security steering committee is composed of business leaders. This is because the information security steering committee is responsible for overseeing the organization's information security program and by having business leaders on the steering committee, it ensures that information security is aligned with the organization's business goals.
The BEST indicator that information security governance and corporate governance are integrated is when the board is regularly informed of information security key performance indicators (KPIs) (Option C). This demonstrates that information security is being monitored and managed at the highest level of the organization, ensuring alignment with overall business objectives and strategic priorities (CoPilot)
Most CISM questions have a key word, this question is integrate. When it comes to The board and KPIs the key word in that answer for me would be support. When it comes to steering committee I think of integration.
C. The board is regularly informed of information security key performance indicators (KPIs).
When the board is regularly informed about information security key performance indicators, it demonstrates a strong integration of information security governance with corporate governance. This means that information security is considered a critical aspect of overall business strategy and decision-making. Regular reporting to the board helps align information security efforts with business objectives and ensures that security is viewed as an integral part of the organization's governance structure.
While the other options (A, B, and D) are important considerations for effective information security governance, regular reporting to the board about key performance indicators directly involves top-level decision-makers and signifies a high level of integration between information security and corporate governance.
D. The information security steering committee is composed of business leaders. C. is wrong because the Board of Directors of an organization don't usually focus on Metrics like KPIs. These are the focus of Management. The Board usually focused on very High-level business objectives. So regularly updating them with KPI's would be some how inappropriate. As such, answer option D makes the most sense.
This option indicates that information security governance and corporate governance are integrated because it demonstrates that the board is taking an active role in overseeing the organization's information security program. By regularly reviewing information security KPIs, the board can ensure that the program is aligned with the organization's overall goals and objectives and that it is effectively managing risk.
having members on the steering committee does not gurantee integration - but KPIs would
This shows that information security decisions and strategies are being made in collaboration with key stakeholders from the business side, which aligns information security efforts with the broader corporate governance framework.
Look at it this way. Should the company have a Corporate governance committee, it would be reporting/aligning to the board, not the security steerco. Board is accountable for governance, not security steerco.
I would go with D as in my opinion this refers to the integration the most.
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.CISM Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
afc1019
Highly Voted 1 year, 3 months agohargit
Most Recent 3 months, 1 week agoPOWNED
10 months, 2 weeks agoMarcelus1714
10 months agoMarcelus1714
10 months agoTamerBeSafe
10 months, 3 weeks agoUncle_Lucifer
1 year agoUncle_Lucifer
1 year agoSoleandheel
1 year agoSoleandheel
1 year agoCyberbug2021
1 year agorichck102
1 year, 1 month agooluchecpoint
1 year, 2 months agoSaisharan
1 year, 2 months agoCISSPST
1 year, 2 months agoiacini
1 year, 3 months ago