正解:C
Explanation
Information security governance is the subset of enterprise governance that provides strategic direction, ensures that objectives are achieved, manages risk appropriately, uses organizational resources responsibly, and monitors the success or failure of the enterprise security program. Information security governance is essential for ensuring that an organization's information assets are protected from internal and external threats, and that the organization complies with relevant laws and standards.
Demonstrated support from which of the following roles in an organization has the most influence over information security governance? The answer is C, the board of directors. The board of directors is the highest governing body of an organization, responsible for overseeing its strategic direction, performance, and accountability. The board of directors sets the tone at the top for information security governance by:
Establishing a clear vision, mission, and values for information security Approving and reviewing information security policies and standards Allocating sufficient resources and budget for information security Appointing and empowering a chief information security officer (CISO) or equivalent role Holding management accountable for information security performance and compliance Communicating and promoting information security awareness and culture The board of directors has the most influence over information security governance because it has the ultimate authority and responsibility for ensuring that information security is aligned with the organization's business objectives, risks, and stakeholder expectations.
References:
10: What is Information Security Governance? - RiskOptics - Reciprocity
11: Information Security Governance and Risk Management | Moss Adams
12: ISO/IEC 27014:2020 - Information security, cybersecurity and privacy ...