Security works only when people know who decides, who does the work and who checks it. CISM expects you to know the standard roles and where accountability sits. The board of directors sets overall direction and risk appetite and oversees management; it is ultimately accountable for protecting the organization's assets. Executive management, led by the chief executive officer (CEO), turns that direction into strategy, funds it and makes sure the organization carries it out. Board committees, such as an audit committee or a risk committee, often receive security reports on the board's behalf.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.