Exam CISM All QuestionsBrowse all questions from this exam
Question 900

Which of the following should be done FIRST when developing an information security strategy?

    Correct Answer: B

    When developing an information security strategy, the first thing to do is to determine the desired state of information security. This step is critical as it defines the overall goals and objectives that the security efforts aim to achieve. Without understanding where the organization wants to be in terms of information security, it is impossible to create effective strategies, policies, and measures to get there. Establishing the vision for the desired security posture sets the foundation for all subsequent actions and decisions in the strategy development process.

Discussion
yottabyteOption: A

leaning towards A for this one. we won't be able to determine the desired state before establishing the strategy. The steering committee is required is drive the strategy and align towards business strategies.

oluchecpointOption: B

Determine the desired state of information security: This is the foundational step in developing a security strategy. You need to understand where you want to be in terms of security before you can make decisions on how to get there.

Y0GAOption: B

GPT4o goes with B. Always tell it to use CISM guidelines to determine answer. It seems to be relatively accurate.

shootnotOption: B

B- Not going too much out of the question then it's B. It's like a question about what the first step of a certain recipe is not to hire a chef and build a kitchen but the recipe itself.

Cyberbug2021

Who determines the " Determine the desired state of information security" ?

richck102Option: B

B. Determine the desired state of information security.

mpc5520Option: B

B could be gap¿?