QuestionQ245

Information Security Governance

Which of the following is MOST important to incorporate into an information security strategy?

  • A Industry benchmarks
  • B Stakeholder requirements
  • C Risk register
  • D Regulatory requirements
Explanation

An information security strategy should align security objectives, priorities, and investments with stakeholder requirements, including the organization’s business needs and risk appetite. Regulatory requirements and the risk register are important inputs to that strategy, but they do not by themselves establish its overall direction.

Community Discussion

No comments yet. Be the first to start the discussion!