Free ISACA CISM Exam Braindumps (page: 59)

The PRIMARY purpose of establishing an information security governance framework should be to:

  1. align information security strategy and investments to support organizational activities
  2. align corporate governance, activities, and investments to information security goals
  3. establish the business case for strategic integration of information security in organizational efforts
  4. document and communicate how the information security program functions within the organization

Answer(s): A



Which of the following is MOST important to have in place to help ensure an organization's cybersecurity program meets the needs of the business?

  1. Information security awareness training
  2. Information security metrics
  3. Risk assessment program
  4. Information security governance

Answer(s): D



Which of the following is the MOST likely outcome from the implementation of a security governance framework?

  1. Increased availability of information systems
  2. Compliance with international standards
  3. Realized business value from information security initiatives
  4. Cost reduction of information security initiatives

Answer(s): C



Which of the following is the BEST indication that information security is integrated into corporate governance?

  1. New vulnerabilities are reported directly to the security manager.
  2. Significant incidents are escalated to executive management.
  3. Security policy documents are reviewed periodically.
  4. Administrative staff is trained on current information security topics.

Answer(s): D



Viewing page 59 of 430
Viewing questions 233 - 236 out of 1716 questions



Post your Comments and Discuss ISACA CISM exam prep with other Community members:

CISM Exam Discussions & Posts