Free ISACA CISM Exam Braindumps (page: 62)

What is the PRIMARY objective of assigning classifications to information assets?

  1. Identify appropriate levels of protection.
  2. Identify business owners and information custodians.
  3. Demonstrate compliance with regulatory requirements.
  4. Maintain an accurate IT asset inventory.

Answer(s): A



An organization engages a third-party vendor to monitor and support a financial application under scrutiny by regulators. Maintaining strict data integrity and confidentiality for this application is critical to the business.
Which of the following controls would MOST effectively manage risk to the organization?

  1. Implementing segregation of duties between systems and data
  2. Activating access and data logging
  3. Disabling vendor access and only re-enabling when access is needed
  4. Implementing periodic access reviews of vendor employees

Answer(s): B



A regulatory compliance issue has been identified in a critical business application, but remediating the issue would significantly impact business operations. What information would BEST enable senior management to make an informed decision?

  1. Impact analysis and treatment options
  2. Costs associated with compensating controls
  3. Industry benchmarks and best practices
  4. Risk assessment results and recommendations

Answer(s): A



Which of the following is the BEST method for management to obtain assurance of compliance with its security policy?

  1. Review security incident logs.
  2. Train staff on their compliance responsibilities.
  3. Conduct regular independent reviews.
  4. Questionstaff concerning their security duties.

Answer(s): C






Post your Comments and Discuss ISACA CISM exam prep with other Community members:

CISM Exam Discussions & Posts