QuestionQ479

Information Security Governance

Which of the following represents the PRIMARY responsibility of an information security governance committee?

  • A Reviewing the information security risk register
  • B Approving changes to the information security strategy
  • C Discussing upcoming information security projects
  • D Reviewing monthly information security metrics
Explanation

An information security governance committee is accountable for strategic oversight and direction of the security program, including approval of changes to the information security strategy. Risk-register review, project discussion, and metric review inform that oversight but are not its primary responsibility.

Community Discussion

No comments yet. Be the first to start the discussion!