An organisation is forming an information security steering committee to direct its security programme. The information security manager is advising on who should sit on it so that the committee can fulfil its governance role. Which membership profile is most appropriate?
- ASecurity analysts and engineers who operate the day-to-day controls, so that decisions rest on the deepest available technical detail.
- BThe information security manager plus external consultants, so that the committee stays free of internal business bias when setting direction.
- CInternal audit and compliance officers, so that the committee can independently verify that controls already meet regulatory obligations.
- DSenior leaders from major business units alongside key support functions, so that security decisions reflect enterprise priorities and shared ownership. Correct
Why A is wrong: Tempting because technical depth seems valuable, but operational staff lack the authority to set direction and bind business units to enterprise-level decisions.
Why B is wrong: Tempting as a route to objectivity, but excluding business leaders strips the committee of the authority and ownership needed to govern effectively.
Why C is wrong: Tempting because assurance matters, but audit and compliance provide oversight, not direction, and their independence is compromised if they set the strategy they later review.
Why D is correct: A cross-functional group of business leaders lets the committee align security with business goals and commit resources, which is its intended governance purpose.