The correct answer is C because information security policy should reflect the organization’s risk appetite, business objectives, and governance direction. Risk appetite defines the amount and type of risk the organization is willing to accept in pursuit of its objectives. Policies establish management’s expectations for protecting information assets, so they must be aligned with the level of risk the organization is prepared to tolerate. Security team capabilities may influence implementation planning, but they should not be the primary driver of policy. Industry benchmarks can help compare practices, but they may not reflect the organization’s specific business context or risk tolerance. Vulnerability scan results identify technical weaknesses, but they are too narrow to guide enterprise-level policy updates. In CISM, policies are governance instruments that communicate required behavior and control expectations. Therefore, risk appetite is the most useful input because it ensures the updated policy supports business priorities and risk-based decision-making.
[Reference: CISM Information Security Governance; policy management, risk appetite, enterprise objectives, and governance alignment principles., , ]
Submit