QuestionQ113
Information Security ManagementA large software development organization has an information security manager who creates policies and standards for use throughout the organization. Security experts are present in every product team and report to their individual product managers. Everyone follows the agreed security policies and procedures, but some teams do not perceive significant value from them.
What is the BEST approach for the organization to improve the value obtained from its information security policies, plans, and controls?
- A Create an informal security forum to share contributions from across the organization and encourage collaboration
- B Modify reporting lines so that all security experts report to the information security department rather than to individual product teams
- C Require all product teams to use a common set of tools with automation that enforces the security standards
- D Appoint a chief information security officer with the authority to enforce information security requirements
Community Discussion