QuestionQ24

Information Security Management

A large organization has a small, centralized information security management team, while most information security work is delegated to many independent product teams. The central team sets policy and recommends tools and automation, but each product team decides how it will meet the policy.

What is the BEST approach to ensure that information security is managed consistently throughout the organization?

  • A Security experts in the product teams should report directly to the centralized information security management team
  • B The centralized team should create an information security center of excellence to help the security experts collaborate
  • C The centralized team should produce detailed process documentation to be followed by all product teams
  • D The organization should adopt a security standard such as ISO/IEC 27001 and enforce its use across the product teams
Explanation

An information security center of excellence enables the security specialists embedded in independent product teams to collaborate, share effective practices, and apply central policy consistently while preserving each team’s responsibility for implementation decisions.

Community Discussion

No comments yet. Be the first to start the discussion!