Question

In: Computer Science

The BEST way to ensure information security efforts and initiatives continue to support corporate strategy is...

The BEST way to ensure information security efforts and initiatives continue to support corporate strategy is by:

A. including the CIO in the information security steering committee
B. conducting benchmarking with industry best practices
C. including information security metrics in the organizational metrics
D. performing periodic internal audits of the information security program

Correct Answer: C????? or D??????????????

______________________

Note

■ Some experts claim that the correct answer is: "C. including information security metrics in the organizational metrics"

■ Other experts claim that the correct answer is: "D. performing periodic internal audits of the information security program"

■ What do you think about that? Please explains: Why B and "not" C......or.......Why C and "not" B

Many thanks!

Solutions

Expert Solution

The security matrix allows the user to interact with data. like which data is available to which user.

In big organizations Sensitive data is not accessible to employees or interns it is only accessible to senior managers and other heads. So if the organization wants to maintain the security of data then they have to implement the Security matrix.

In simple words, we can say that the Security matrix is used to assign roles to users. For example a person working with IT should not have access to crucial information on the mechanical team or electronics team.

Another example is if a person leaves an organization then his/her access rights should be revoked that person should not be allowed to access the information of that organization.

Internal audit on information systems is an independent assessment of the system for knowing about vulnerabilities, and other security issues. The goal of an audit is to minimize security issues.

internal audit is very important in highlighting information security and privacy risks in an organization.

Both are very important With respect to information security.

But in Question, it mentioned ensuring security and good initiative so I think correct is

C: Including information security metrics in the organizational metrics

it is a good initiative to give different access to the different employees so implementing this information security matrix should be implemented with organizations matrix.

Both answers to the questions are correct but I think in most organizations security matrix is a priority than internal audits.


Related Solutions

How important is it to involve physicians in financial improvement efforts? What is the best strategy...
How important is it to involve physicians in financial improvement efforts? What is the best strategy for physician engagement?
If employee-investors are unsophisticated and unlikely to be materially influenced by educational efforts, the best way...
If employee-investors are unsophisticated and unlikely to be materially influenced by educational efforts, the best way to improve the welfare of employee-investors is pension design. Discuss.
What is the best way for senior project managers to ensure that all the financial aspects...
What is the best way for senior project managers to ensure that all the financial aspects of a project are completed and documented
How will you ensure that all appropriate audiences receive information about research and EBP initiatives?
How will you ensure that all appropriate audiences receive information about research and EBP initiatives?
How does the large range of different mobile devices impact corporate efforts to secure corporate information?...
How does the large range of different mobile devices impact corporate efforts to secure corporate information? Explain.
Discuss telecommunication operations and three (3) security measures to ensure     protection of information.
Discuss telecommunication operations and three (3) security measures to ensure     protection of information.
5. What is the best way to successfully get an approved application for social security DISABILITY...
5. What is the best way to successfully get an approved application for social security DISABILITY benefits? 6. Why is HSA more in favor over FSA?
1. List the best practices for a corporate password security policy. 2. List and describe the...
1. List the best practices for a corporate password security policy. 2. List and describe the best practices for a corporate password security policy. 3. List and describe the best practices for a corporate physical security policy. 4. List and describe the best practices for a corporate digital security policy. 5. List and describe the best practices for a corporate printer security policy.
For a Clinical Decision Support System: create a policy to ensure compliance with health information, data...
For a Clinical Decision Support System: create a policy to ensure compliance with health information, data exchange or industry infrastructure standards.
How you would weigh the risks involved in your corporate long-term funding strategy to ensure you...
How you would weigh the risks involved in your corporate long-term funding strategy to ensure you would not jeopardize success and the expectations of investors?
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT