ISACA CISM Exam Questions
Certified Information Security Manager (Page 43 )

Updated On: 19-Feb-2026

In information security governance, the PRIMARY role of the board of directors is to ensure:

  1. approval of relevant policies and standards.
  2. communication of security posture to stakeholders.
  3. compliance with regulations and best practices.
  4. alignment with the strategic goals of the organization.

Answer(s): D



Which of the following is the STRONGEST indicator of effective alignment between corporate governance and information security governance?

  1. Senior management sponsors information security efforts.
  2. Senior management requests periodic information security updates.
  3. Key performance indicators (KPIs) for controls trend positively.
  4. Information security initiatives meet scope. schedule, and budget.

Answer(s): C



Which of the following should be the PRIMARY consideration when developing a security governance framework for an enterprise?

  1. Understanding of the current business strategy
  2. Assessment of the current security architecture
  3. Results of a business impact analysis (BIA)
  4. Benchmarking against industry best practice

Answer(s): A



Who should decide the extent to which an organization will comply with new cybersecurity regulatory requirements?

  1. Senior management
  2. IT steering committee
  3. Legal counsel
  4. Information security manager

Answer(s): A



Which of the following would BEST help an information security manager prioritize remediation activities to meet regulatory requirements?

  1. A capability maturity model matrix
  2. Annual loss expectancy (ALE) of noncompliance
  3. Cost of associated controls
  4. Alignment with the IT strategy

Answer(s): D






Post your Comments and Discuss ISACA CISM exam dumps with other Community members:

Join the CISM Discussion