QUESTION IMAGE
Question
according to johnson, goetz, and pfleeger, what do chief information security officers widely agree that action plans must include?
risk categorization
communication
measurement
these are all things that should be included in an action plan.
Identify the core question
The question asks what Chief Information Security Officers (CISOs) widely agree that action plans must include, according to Johnson, Goetz, and Pfleeger.
Analyze the literature context
In cybersecurity management literature, specifically regarding security metrics and governance (often referenced in works by Johnson, Goetz, and Pfleeger), CISOs emphasize that security action plans cannot succeed in a vacuum. They require:
- Risk Categorization to prioritize actions.
- Communication to ensure organizational alignment.
- Measurement (metrics) to track progress and effectiveness.
These elements are all fundamental pillars of Cybersecurity Basics when designing strategic security initiatives.
Evaluate the options
- Risk Categorization: Necessary for scoping and prioritization.
- Communication: Essential for stakeholder buy-in and execution.
- Measurement: Critical for determining if the plan is working.
- These are all things that should be included in an action plan: Since all three individual components are widely recognized as vital, this comprehensive option is the correct choice.
Snap & solve any problem in the app
Get step-by-step solutions on Sovi AI
Photo-based solutions with guided steps
Explore more problems and detailed explanations
- (A) Risk Categorization
- (B) Communication
- (C) Measurement
- (D) These are all things that should be included in an action plan. (Correct answer)