CISM Certified Information Security Manager – Question0170

Which of the following is a PRIMARY responsibility of the information security governance function?

A.
Defining security strategies to support organizational programs
B. Ensuring adequate support for solutions using emerging technologies
C. Fostering a risk-aware culture to strengthen the information security program
D. Advising senior management on optimal levels of risk appetite and tolerance

Correct Answer: A