In implementing information security governance, the information security manager is PRIMARILY responsible for:

In implementing information security governance, the information security manager is PRIMARILY responsible for:
A . developing the security strategy.
B . reviewing the security strategy.
C . communicating the security strategy.
D . approving the security strategy

Answer: A

Explanation:

The information security manager is responsible for developing a security strategy based on business objectives with the help of business process owners. Reviewing the security strategy is the responsibility of a steering committee. The information security manager is not necessarily responsible for communicating or approving the security strategy.

Latest CISM Practice Questions with 1327 Q&As

Updated Study Material | Instant Download | Detailed Answers and Explanations

Subscribe
Notify of
guest
0 Comments