Free ISACA CISM Exam Braindumps (page: 55)

Which of the following should an information security manager do FIRST after learning about a new regulation that affects the organization?

  1. Evaluate the changes with legal counsel.
  2. Notify the affected business units.
  3. Assess the noncompliance risk.
  4. Inform senior management of the new regulation.

Answer(s): A



Which of the following should be the FIRST step to ensure an information security program meets the requirements of new regulations?

  1. Validate the asset classification schema.
  2. Integrate compliance into the risk management process.
  3. Assess organizational security controls.
  4. Conduct a gap analysis to determine necessary changes.

Answer(s): B



Which of the following is MOST important to consider when handling digital evidence during the forensics investigation of a cybercrime?

  1. Business strategies
  2. Industry best practices
  3. Global standards
  4. Local regulations

Answer(s): D



A legacy application does not comply with new regulatory requirements to encrypt sensitive data at rest, and remediating this issue would require significant investment. What should the information security manager do FIRST?

  1. Investigate alternative options to remediate the noncompliance.
  2. Assess the business impact to the organization.
  3. Present the noncompliance risk to senior management.
  4. Determine the cost to remediate the noncompliance.

Answer(s): B



Viewing page 55 of 430
Viewing questions 217 - 220 out of 1716 questions



Post your Comments and Discuss ISACA CISM exam prep with other Community members:

CISM Exam Discussions & Posts