Free CISM Exam Braindumps (page: 39)

Page 39 of 430

When developing an information security governance framework, which of the following would be the MAINimpact when lacking senior management involvement?

  1. Accountability for risk treatment is not clearly defined.
  2. Information security responsibilities are not communicated effectively.
  3. Resource requirements are not adequately considered.
  4. Information security plans do not support business requirements.

Answer(s): C



Which of the following is the BEST way to facilitate the alignment between an organization’s information security program and business objectives?

  1. Information security is considered at the feasibility stage of all IT projects.
  2. The information security governance committee includes representation from key business areas.
  3. The chief executive officer reviews and approves the information security program.
  4. The information security program is audited by the internal audit department.

Answer(s): B



The effectiveness of the information security process is reduced when an outsourcing organization:

  1. is responsible for information security governance activities
  2. receives additional revenue when security service levels are met
  3. incurs penalties for failure to meet security service-level agreements
  4. standardizes on a single access-control software product

Answer(s): A



What should be an information security manager’s FIRST course of action when an organization is subject to a new regulatory requirement?

  1. Perform a gap analysis
  2. Complete a control assessment
  3. Submit a business case to support compliance
  4. Update the risk register

Answer(s): A






Post your Comments and Discuss ISACA CISM exam with other Community members:

CISM Exam Discussions & Posts