Which of the following is MOST important to the effectiveness of an information security program?
A.
Security metrics
B.
Organizational culture
C.
IT governance
D.
Risk management
The Answer Is:
D
This question includes an explanation.
Explanation:
Risk management is the most important factor for the effectiveness of an information security program, as it provides a systematic and consistent approach to identify, assess, treat, and monitor the information security risks that could affect the organization’s objectives. Risk management also helps to align the security program with the business strategy, prioritize the security initiatives and resources, and communicate the value of security to the stakeholders.