SY0-701 Question 402
Single answer5.1 Summarize elements of effective security governance.A healthcare company is expanding into two new states and must align its security program with stricter privacy obligations while also reducing inconsistent security practices across business units. The CIO wants a governance improvement that will give executives clear oversight, define how security decisions are made, and ensure that new technical controls are implemented consistently based on business risk and regulatory requirements. Which of the following is the BEST action to take first?
- A
Establish a formal security governance committee with executive sponsorship, define policy and standards, and require risk-based reviews for major security decisions
- B
Purchase a new SIEM platform so security events from all business units can be monitored centrally before updating policies
- C
Require each business unit to select its own security controls to address local operational needs without centralized approval
- D
Conduct monthly vulnerability scans and treat the scan results as the organization’s primary governance mechanism
Show answer and explanation
Correct answer: A
Explanation
The best answer is to establish a formal governance structure led by executive sponsorship and supported by policies, standards, and risk-based decision processes. In Security+, effective security governance includes aligning security efforts to business goals, assigning roles and responsibilities, creating and enforcing policies and standards, and ensuring oversight through leadership and committees or similar bodies. In a regulated environment such as healthcare, governance must also account for compliance obligations and enterprise risk.
Industry best practices support this approach. NIST guidance, including the Cybersecurity Framework and NIST SP 800-100, emphasizes governance, risk management, and organizational oversight as foundational elements of an effective security program. Similarly, common governance models stress that senior leadership sets direction, approves risk tolerance, and ensures accountability. Technical tools such as SIEMs and activities such as vulnerability scanning are important, but they are subordinate to governance and should operate within an approved policy and risk management framework.
- A. Correct.
Correct. Effective security governance starts with leadership, accountability, and formal decision-making structures. A governance committee with executive sponsorship helps align security with business objectives, legal obligations, and risk tolerance. Defining policy and standards creates consistency across business units, and requiring risk-based reviews ensures that control selection is driven by organizational risk and compliance needs rather than ad hoc technical preferences. This is a foundational governance activity.
- B. Incorrect.
Incorrect. Centralized monitoring can improve security operations, but a SIEM is a technical tool, not a governance framework. Without policies, standards, roles, and oversight, the organization may collect more data but still lack consistent decision-making and accountability. This option reflects the common misconception that buying technology can replace governance.
- C. Incorrect.
Incorrect. Allowing each business unit to independently choose controls without centralized governance increases inconsistency and makes it harder to demonstrate compliance, enforce standards, and manage enterprise risk. Local input is valuable, but governance should provide overarching direction, approved standards, and accountability.
- D. Incorrect.
Incorrect. Vulnerability scanning is an operational security activity that supports risk management, but it does not by itself establish governance. Governance includes policies, oversight, roles, authority, and alignment with business and regulatory requirements. Treating scan results as the primary governance mechanism confuses technical assessment with management oversight.