Scenario: An organization has recently appointed a CISO. This is a new role in the organization and it signals the increasing need to address security consistently at the enterprise level. This new CISO, while confident with skills and experience, is constantly on the defensive and is unable to advance the IT security centric agenda.
From an Information Security Leadership perspective, which of the following is a MAJOR concern about the CISO's approach to security?
Which of the following is of MOST importance when security leaders of an organization are required to align security to influence the culture of an organization?
Which of the following is the PRIMARY purpose of International Organization for Standardization (ISO)
27001?
Which of the following is the MOST important reason to measure the effectiveness of an Information Security Management System (ISMS)?