ISACA CISM Exam Questions
Certified Information Security Manager (Page 46 )

Updated On: 19-Feb-2026

Which of the following BEST demonstrates that the objectives of an information security governance framework are being met?

  1. Risk dashboard
  2. Key performance indicators (KPIs)
  3. Penetration test results
  4. Balanced scorecard

Answer(s): D



Which of the following would BEST enable integration of information security governance into corporate governance?

  1. Ensuring appropriate business representation on the information security steering committee
  2. Using a balanced scorecard to measure the performance of the information security strategy
  3. Implementing IT governance, risk and compliance (IT GRC) dashboards
  4. Having the CIO chair the information security steering committee

Answer(s): C



Which of the following BEST enables effective information security governance?

  1. Periodic vulnerability assessments
  2. Established information security metrics
  3. Advanced security technologies
  4. Security-aware corporate culture

Answer(s): D



The PRIMARY reason to classify information assets should be to ensure:

  1. proper access control.
  2. senior management buy-in.
  3. insurance valuation is appropriate.
  4. proper ownership is established.

Answer(s): D



Which of the following would be MOST useful when illustrating to senior management the status of a recently implemented information security governance framework?

  1. A risk assessment
  2. A threat assessment
  3. A maturity model
  4. Periodic testing results

Answer(s): C






Post your Comments and Discuss ISACA CISM exam dumps with other Community members:

Join the CISM Discussion