Free CISM Exam Braindumps (page: 38)

Page 38 of 430

Business units within an organization are resistant to proposed changes to the information security program. Which of the following is the BEST way to address this issue?

  1. Implementing additional security awareness training
  2. Communicating critical risk assessment results to business unit managers
  3. Including business unit representation on the security steering committee
  4. Publishing updated information security policies

Answer(s): B



In addition to business alignment and security ownership, which of the following is MOST critical for information security governance?

  1. Auditability of systems
  2. Compliance with policies
  3. Reporting of security metrics
  4. Executive sponsorship

Answer(s): A



Senior management has allocated funding to each of the organization’s divisions to address information security vulnerabilities. The funding is based on each division’s technology budget from the previous fiscal year. Which of the following should be of GREATEST concern to the information security manager?

  1. Areas of highest risk may not be adequately prioritized for treatment
  2. Redundant controls may be implemented across divisions
  3. Information security governance could be decentralized by division
  4. Return on investment may be inconsistently reported to senior management

Answer(s): A



The effectiveness of an information security governance framework will BEST be enhanced if:

  1. IS auditors are empowered to evaluate governance activities
  2. risk management is built into operational and strategic activities
  3. a culture of legal and regulatory compliance is promoted by management
  4. consultants review the information security governance framework

Answer(s): D






Post your Comments and Discuss ISACA CISM exam with other Community members:

CISM Exam Discussions & Posts