CISM - Information Security Program - Section 3.1

Plan and manage information security programme resources including people, tools and technologies.

Plan and manage the people, tooling, and technologies required to operate an information security programme through structured resource management and capacity planning. Recognise when staffing gaps or tool deficiencies create programme risks and determine the appropriate response, such as hiring, outsourcing, or technology investment.

Resource managementSecurity staffingToolingCapacity planning

Practice question for this objective

Free sampleInformation Security Programeasy

An information security manager is structuring the organisation's governance documents. Senior management wants a single document that states, at a high level, management's intent and direction for protecting information assets, while leaving the specific rules and technical settings to lower-level documents. Which type of document should the security manager produce to capture this management intent?

  • AA procedure that lists the ordered steps an administrator follows to configure each security control
  • BA security policy that expresses management's intent and overall direction for protecting information assets Correct
  • CA standard that fixes the mandatory technical settings every system must meet
  • DA guideline that offers recommended good practice for staff to consider
Recognise that a security policy is the top-level document expressing management's intent and direction for protecting information assets. A security policy sits at the top of the document hierarchy and communicates management's intent and direction, which delegates detailed mandatory requirements to standards and detailed actions to procedures.

Why A is wrong: Tempting because procedures are formal governance documents, but a procedure gives step-by-step instructions for a task, not the high-level statement of management intent the scenario asks for.

Why B is correct: Correct: a policy is the highest-level governance document and exists precisely to state management's intent and direction at a high level, with the detail left to standards and procedures.

Why C is wrong: Tempting because standards are mandatory and authoritative, but a standard specifies detailed mandatory requirements that support a policy rather than expressing the overarching management intent.

Why D is wrong: Tempting because guidelines are part of the document hierarchy, but guidelines are advisory recommendations, so they cannot carry management's binding statement of intent and direction.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Program objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.