QuestionQ240

Information Security Governance

Which of the following BEST facilitates the integration of information security governance with corporate governance?

  • A Senior management approval of the information security strategy
  • B Clear lines of authority across the organization
  • C An information security steering committee with business representation
  • D Well-documented information security policies and standards
Explanation

A cross-functional information security steering committee with business representation provides a formal governance mechanism to align security decisions, risks, priorities, and investments with business objectives and corporate oversight. ISACA identifies centralized cross-functional cybersecurity steering committees as a means of providing integrated cybersecurity-risk assessment and aligning governance with enterprise needs.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!