QuestionQ932

Information Security Governance

Which of the following should be performed FIRST when creating an information security governance framework?

  • A Gain an understanding of the business and cultural attributes.
  • B Contract a third party to conduct an independent review of the program.
  • C Conduct a cost-benefit analysis of the framework.
  • D Evaluate information security tools and skills relevant for the environment.
Explanation

Information security governance must align with business objectives and operate effectively within the organization’s culture. Understanding those business and cultural attributes provides the context for defining governance, roles, priorities, controls, resource needs, and later assurance activities.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!