QuestionQ113

Information Security Management

A large software development organization has an information security manager who creates policies and standards for use throughout the organization. Security experts are present in every product team and report to their individual product managers. Everyone follows the agreed security policies and procedures, but some teams do not perceive significant value from them.

What is the BEST approach for the organization to improve the value obtained from its information security policies, plans, and controls?

  • A Create an informal security forum to share contributions from across the organization and encourage collaboration
  • B Modify reporting lines so that all security experts report to the information security department rather than to individual product teams
  • C Require all product teams to use a common set of tools with automation that enforces the security standards
  • D Appoint a chief information security officer with the authority to enforce information security requirements
Explanation

A collaborative security forum enables security specialists and product teams to exchange feedback, share useful practices, and align security requirements with product and business objectives. This builds stakeholder engagement and demonstrates security as a business enabler, improving perceived value without unnecessarily changing reporting structures or imposing additional enforcement.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!