The PRIMARY objective for information security program development should be:
A.
Reducing the impact of the risk to the business.
B.
Establishing strategic alignment with bunsiness continuity requirements
C.
Establishing incident response programs.
D.
Identifying and implementing the best security solutions.
The Answer Is:
A
This question includes an explanation.
Explanation:
Objective of Information Security Programs:
The primary objective of an information security program is to manage risks in a manner that aligns with business goals and minimizes the impact of potential security incidents. This involves identifying risks, implementing appropriate controls, and ensuring that security measures are integrated into the organization’s overall risk management framework.
Risk-Centric Approach:
The EC-Council emphasizes that information security programs should not merely focus on compliance or deploying the latest tools but on reducing risks that could disrupt business processes or cause harm to assets.
Alignment with Business Continuity:
While strategic alignment with business continuity requirements (Option B) is critical, it is part of the broader objective of reducing the overall impact of risks on the business.
References:
This is highlighted in the EC-Council’s emphasis on aligning security initiatives with business strategies while prioritizing risk mitigation.
712-50 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"