cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Mahender
Newcomer II

Security governance

Optimally, security governance is performed by a board of directors, but smaller organizations may simply have the CEO or CISO perform the activities of security governance. Which
of the following is true about security governance?
A. Security governance ensures that the requested activity or access to an object is possible
given the rights and privileges assigned to the authenticated identity.
B. Security governance is used for efficiency. Similar elements are put into groups, classes,
or roles that are assigned security controls, restrictions, or permissions as a collective.
C. Security governance is a documented set of best IT security practices that prescribes
goals and requirements for security controls and encourages the mapping of IT security
ideals to business objectives.
D. Security governance seeks to compare the security processes and infrastructure used
within the organization with knowledge and insight obtained from external sources.

 

Hard to believe on the answer given by ISC2 which is D, but the correct answer is C. Correct me if I am wrong?

11 Replies
Mahender
Newcomer II

Yes sir, it's CISSP ISC2 Official 9th edition guide in PDF format. Seems it will be addressed below by Wiley & Sons publications. Sorry for the delayed response.
JohnEricsson
Newcomer I

I answered "C" but now think "D" is best.

 

For "C", I would say "Security Governance" (SG) is an oversight that a standard is being met. I think what the answer says is part of the oversight, but not SG itself.  

 

For "D", SG is the top tier of oversight, While it does not set the standard (that could be management instruction), SG role is to make sure it is being met (see answer C as to how) and provide assurance of it. However it can not  do that in isolation, it needs external input to determine best practice, it needs external input to determine new risks (e.g. supply chain with AI python repositories). 

 

However I could be CISSP definition of SG is different to mine.