Free ISACA CISM Exam Braindumps (page: 60)

Which of the following is MOST important for guiding the development and management of a comprehensive information security program?

  1. Adopting information security program management best practices
  2. Implementing policies and procedures to address the information security strategy
  3. Establishing and maintaining an information security governance framework
  4. Aligning the organization's business objectives with IT objectives

Answer(s): C



Which of the following is the BEST way for senior leadership to demonstrate commitment for an effective information security strategy?

  1. Appointing the top information security role to report to the CEO
  2. Communicating organizational risk appetite and tolerance
  3. Approving a comprehensive risk management program
  4. Allocating adequate resources for information security

Answer(s): D



An organization is considering the adoption of cloud service providers for its expanding global business operations. Which of the following is MOST important for the information security manager to review with regard to data protection?

  1. Data privacy policy
  2. Security policy and standards
  3. Organizational requirements
  4. Local laws and regulations

Answer(s): A



In a multinational organization, local security regulations should be implemented over global security policy because:

  1. deploying awareness of local regulations is more practical than of global policy.
  2. global security policies include unnecessary controls for local businesses.
  3. business objectives are defined by local business unit managers.
  4. requirements of local regulations take precedence.

Answer(s): D



Viewing page 60 of 430
Viewing questions 237 - 240 out of 1716 questions



Post your Comments and Discuss ISACA CISM exam prep with other Community members:

CISM Exam Discussions & Posts