The correct answer is C because staff are more likely to report information security issues when leadership establishes a positive security culture. A positive culture encourages openness, trust, accountability, and timely reporting without fear of unfair blame. In CISM governance, information security is not only a technical function; it depends heavily on behavior, communication, leadership support, and organizational values. Tabletop exercises are useful for testing incident response readiness, but they do not necessarily encourage everyday reporting by all staff. Incentives for security skills training may improve participation in learning activities, but they do not directly create a reporting culture. Formal incident response processes are important because they define how incidents are handled, but processes alone may not motivate employees to report concerns if the culture is negative or punitive. Leadership behavior is critical because employees follow the tone set by management. Therefore, leaders setting a positive security culture is the best way to encourage staff to report information security issues.
[Reference: CISM Information Security Governance; security culture, leadership commitment, awareness, reporting, and accountability principles., , ]
Submit