Which of the following is the BEST indication that an organization has a mature information security culture?
The BEST indication that an organization has a mature information security culture is when its staff consistently consider risk in making decisions. When an organization's staff understands the risks associated with their actions and are empowered to make risk-informed decisions, it indicates that the organization has a mature information security culture.
According to the Certified Information Security Manager (CISM) Study Manual, 'A mature information security culture exists when the people within the organization understand and appreciate the risks associated with information and technology and when they take steps to manage those risks on a daily basis.'
While information security training, documented information security policies, and regular interaction between the chief information security officer (CISO) and the board are all important components of a mature information security culture, they are not sufficient on their own. It is only when staff consistently consider risk in making decisions that an organization's information security culture can be considered mature.
Certified Information Security Manager (CISM) Study Manual, 15th Edition, Pages 151-152.
Delfina
10 hours agoAdelle
6 days agoShizue
11 days agoWava
16 days agoKenda
21 days agoNieves
26 days agoNieves
1 month agoDawne
1 month agoMy
1 month agoMilly
2 months agoIrene
2 months agoZena
2 months agoAntonio
2 months agoErick
2 months agoAmalia
2 months agoOcie
3 months agoCherry
3 months agoChauncey
3 months agoBette
3 months ago