Free CISM Exam Braindumps (page: 43)

Page 43 of 430

Which of the following is the BEST way to align security and business strategies?

  1. Include security risk as part of corporate risk management.
  2. Develop a balanced scorecard for security.
  3. Establish key performance indicators (KPIs) for business through security processes.
  4. Integrate information security governance into corporate governance.

Answer(s): C



When developing an information security governance framework, which of the following should be the FIRSTactivity?

  1. Integrate security within the system’s development life-cycle process.
  2. Align the information security program with the organization’s other risk and control activities.
  3. Develop policies and procedures to support the framework.
  4. Develop response measures to detect and ensure the closure of security breaches.

Answer(s): B



Which of the following is the MOST effective way for senior management to support the integration of information security governance into corporate governance?

  1. Develop the information security strategy based on the enterprise strategy.
  2. Appoint a business manager as heard of information security.
  3. Promote organization-wide information security awareness campaigns.
  4. Establish a steering committee with representation from across the organization.

Answer(s): A



Which of the following would BEST help to ensure the alignment between information security and business functions?

  1. Developing information security policies
  2. Establishing an information security governance committee
  3. Establishing a security awareness program
  4. Providing funding for information security efforts

Answer(s): B






Post your Comments and Discuss ISACA CISM exam with other Community members:

CISM Exam Discussions & Posts