The correct answer is C because information security risk management is most effectively aligned with business objectives when it is integrated into the organization’s broader governance and enterprise risk management framework. This ensures security risks are evaluated alongside strategic, operational, financial, legal, and compliance risks. It also enables consistent risk appetite, reporting, ownership, escalation, and decision-making across the enterprise. Mandating ERM policy enforcement may support consistency, but enforcement alone does not ensure that information security risk is properly governed and integrated. Implementing multiple layers of technical controls may reduce some risks, but technical controls alone may not align with business priorities or risk appetite. Annual training is useful for awareness, but it is not sufficient to align risk management with business objectives. CISM emphasizes governance, business alignment, risk ownership, and integration with enterprise risk processes. Therefore, establishing an information security governance framework integrated with ERM is the best answer.
[Reference: CISM Information Risk Management; enterprise risk management, governance integration, business alignment, and risk ownership principles., , ]
Submit