Which of the following is the BEST indication that an organization has a mature information security culture?
The BEST indication that an organization has a mature information security culture is when its staff consistently consider risk in making decisions. When an organization's staff understands the risks associated with their actions and are empowered to make risk-informed decisions, it indicates that the organization has a mature information security culture.
According to the Certified Information Security Manager (CISM) Study Manual, 'A mature information security culture exists when the people within the organization understand and appreciate the risks associated with information and technology and when they take steps to manage those risks on a daily basis.'
While information security training, documented information security policies, and regular interaction between the chief information security officer (CISO) and the board are all important components of a mature information security culture, they are not sufficient on their own. It is only when staff consistently consider risk in making decisions that an organization's information security culture can be considered mature.
Certified Information Security Manager (CISM) Study Manual, 15th Edition, Pages 151-152.
Lindsey
1 day agoStanford
6 days agoRoyal
11 days agoStefany
17 days agoAlton
22 days agoJustine
27 days agoDelfina
2 months agoAdelle
2 months agoShizue
2 months agoWava
2 months agoKenda
2 months agoNieves
2 months agoNieves
3 months agoDawne
3 months agoMy
3 months agoMilly
3 months agoIrene
3 months agoZena
3 months agoAntonio
4 months agoErick
4 months agoAmalia
4 months agoOcie
4 months agoCherry
5 months agoChauncey
5 months agoBette
4 months ago