ISACA CISM Exam Questions
Certified Information Security Manager (Page 32 )

Updated On: 19-Feb-2026

The effectiveness of the information security process is reduced when an outsourcing organization:

  1. is responsible for information security governance activities
  2. receives additional revenue when security service levels are met
  3. incurs penalties for failure to meet security service-level agreements
  4. standardizes on a single access-control software product

Answer(s): A



What should be an information security manager’s FIRST course of action when an organization is subject to a new regulatory requirement?

  1. Perform a gap analysis
  2. Complete a control assessment
  3. Submit a business case to support compliance
  4. Update the risk register

Answer(s): A



Internal audit has reported a number of information security issues which are not in compliance with regulatory requirements. What should the information security manager do FIRST?

  1. Create a security exception
  2. Perform a vulnerability assessment
  3. Perform a gap analysis to determine needed resources
  4. Assess the risk to business operations

Answer(s): C



Which of the following is the MOST important reason for an organization to develop an information security governance program?

  1. Establishment of accountability
  2. Compliance with audit requirements
  3. Monitoring of security incidents
  4. Creation of tactical solutions

Answer(s): B



The PRIMARY purpose of aligning information security with corporate governance objectives is to:

  1. build capabilities to improve security processes.
  2. consistently manage significant areas of risk.
  3. identify an organization’s tolerance for risk.
  4. re-align roles and responsibilities.

Answer(s): A






Post your Comments and Discuss ISACA CISM exam dumps with other Community members:

Join the CISM Discussion