CISM Certified Information Security Manager – Question1172

Which of the following is the STRONGEST indication that senior management commitment to information security is lacking within an organization?

A.
A high level of information security risk acceptance
B. The information security manager reports to the chief risk officer
C. Inconsistent enforcement of information security policies
D. A reduction in information security investment

Correct Answer: C