Free ISACA CISM Exam Braindumps (page: 54)

Who should decide the extent to which an organization will comply with new cybersecurity regulatory requirements?

  1. Senior management
  2. IT steering committee
  3. Legal counsel
  4. Information security manager

Answer(s): A



Which of the following would BEST help an information security manager prioritize remediation activities to meet regulatory requirements?

  1. A capability maturity model matrix
  2. Annual loss expectancy (ALE) of noncompliance
  3. Cost of associated controls
  4. Alignment with the IT strategy

Answer(s): D



Which of the following is the PRIMARY reason an information security strategy should be deployed across an organization?

  1. To ensure that the business complies with security regulations
  2. To ensure that management's intent is reflected in security activities
  3. To ensure that employees adhere to security standards
  4. To ensure that security-related industry best practices are adopted

Answer(s): A



Which of the following is the BEST option for addressing regulations that will adversely affect the allocation of information security program resources?

  1. Prioritize compliance efforts based on probability.
  2. Determine compliance levels of peer organizations.
  3. Delay implementation of compliance activities.
  4. Conduct assessments for management decisions

Answer(s): D



Viewing page 54 of 430
Viewing questions 213 - 216 out of 1716 questions



Post your Comments and Discuss ISACA CISM exam prep with other Community members:

CISM Exam Discussions & Posts