Free ISACA CISM Exam Braindumps (page: 45)

Which of the following is a PRIMARY responsibility of an information security governance committee?

  1. Analyzing information security policy compliance reviews
  2. Approving the purchase of information security technologies
  3. Reviewing the information security strategy
  4. Approving the information security awareness training strategy

Answer(s): C



An information security manager discovers that the organization’s new information security policy is not being followed across all departments. Which of the following should be of GREATEST concern to the information security manager?

  1. Different communication methods may be required for each business unit.
  2. Business unit management has not emphasized the importance of the new policy.
  3. The corresponding controls are viewed as prohibitive to business operations.
  4. The wording of the policy is not tailored to the audience.

Answer(s): C



An organization has detected potential risk emerging from noncompliance with new regulations in its industry. Which of the following is the MOST important reason to report this situation to senior management?

  1. The risk profile needs to be updated.
  2. An external review of the risk needs to be conducted.
  3. Specific monitoring controls need to be implemented.
  4. A benchmark analysis needs to be performed.

Answer(s): A



Which of the following is the BEST way for an information security manager to identify compliance with information security policies within an organization?

  1. Analyze system logs.
  2. Conduct security awareness testing.
  3. Perform vulnerability assessments.
  4. Conduct periodic audits.

Answer(s): D



Viewing page 45 of 430
Viewing questions 177 - 180 out of 1716 questions



Post your Comments and Discuss ISACA CISM exam prep with other Community members:

CISM Exam Discussions & Posts