QuestionQ1064

Information Security Governance

An organization is implementing an information security governance framework. To convey the program's effectiveness to stakeholders, it is MOST important to establish:

  • A a control self-assessment (CSA) process.
  • B metrics for each milestone.
  • C automated reporting to stakeholders.
  • D a monitoring process for the security policy.
Explanation

Metrics for each milestone provide objective, measurable evidence of progress and effectiveness that can be communicated to stakeholders. A control self-assessment, automated reporting, or security-policy monitoring may support governance activities but does not by itself establish how program effectiveness is measured.

Community Discussion

No comments yet. Be the first to start the discussion!