A large multinational corporation is implementing a new governance structure to enhance its risk posture. Which of the following executive roles would be the BEST choice to serve as the ultimate authority on enterprise-wide protection policy decisions?
The Chief Information Security Officer (CISO) is the correct answer because this executive-level role is specifically responsible for establishing and maintaining the enterprise security vision, strategy, and program. The CISO has the authority to make enterprise-wide security policy decisions and is accountable for the organization's overall security posture.
While the Data Protection Administrator implements controls according to established policies, they don't have the authority to make high-level policy decisions. The Chief Technology Officer (CTO) focuses primarily on technological innovation and infrastructure rather than security governance. The Compliance Director ensures adherence to regulatory requirements but doesn't typically have authority over comprehensive security policy decisions beyond compliance domains.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are the main responsibilities of a CISO?
Open an interactive chat with Bash
What is the difference between a CISO and a Compliance Director?
Open an interactive chat with Bash
How does the CISO influence the risk posture of an organization?
Open an interactive chat with Bash
ISC2 CISSP
Security and Risk Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access