ISACA CISM Exam Questions
Certified Information Security Manager (Page 35 )

Updated On: 19-Feb-2026

When developing an information security governance framework, which of the following should be the FIRSTactivity?

  1. Integrate security within the system’s development life-cycle process.
  2. Align the information security program with the organization’s other risk and control activities.
  3. Develop policies and procedures to support the framework.
  4. Develop response measures to detect and ensure the closure of security breaches.

Answer(s): B



Which of the following is the MOST effective way for senior management to support the integration of information security governance into corporate governance?

  1. Develop the information security strategy based on the enterprise strategy.
  2. Appoint a business manager as heard of information security.
  3. Promote organization-wide information security awareness campaigns.
  4. Establish a steering committee with representation from across the organization.

Answer(s): A



Which of the following would BEST help to ensure the alignment between information security and business functions?

  1. Developing information security policies
  2. Establishing an information security governance committee
  3. Establishing a security awareness program
  4. Providing funding for information security efforts

Answer(s): B



When establishing an information security governance framework, it is MOST important for an information security manager to understand:

  1. the regulatory environment.
  2. information security best practices.
  3. the corporate culture.
  4. risk management techniques.

Answer(s): A



Which of the following is a PRIMARY responsibility of the information security governance function?

  1. Defining security strategies to support organizational programs
  2. Ensuring adequate support for solutions using emerging technologies
  3. Fostering a risk-aware culture to strengthen the information security program
  4. Advising senior management on optimal levels of risk appetite and tolerance

Answer(s): A






Post your Comments and Discuss ISACA CISM exam dumps with other Community members:

Join the CISM Discussion