Rédigé par des étudiants ayant réussi Disponible immédiatement après paiement Lire en ligne ou en PDF Mauvais document ? Échangez-le gratuitement 4,6 TrustPilot
logo-home
Examen

ISACA CISM 2-15 question & answer 2022-24

Note
-
Vendu
-
Pages
4
Grade
A+
Publié le
03-01-2024
Écrit en
2023/2024

Questions - correct answer Answers and Explanations Decisions regarding information security are best supported by - correct answer effective metrics effective metrics are essential to provide information needed to make decisions. Metrics are quantifiable entity that allows the measurement of the achievement of a process goal. A project manager is developing a developer portal and request that the security manager assign a public IP address so that it can be accessed by in house staff and by external consultants outside the organization's local area network (LAN). What should the security manager do first? - correct answer understand the business requirements of the portal you cannot make an uninformed decision. Learn and understand the business requirement first! Vulernability accessment and Intrustion detection systems (IDS) are subsequent tasks Which of the following should be understood before defining risk management strategies? - correct answer organizational objectives and risk appetite Analyze the org's objectives and risk appetite, then define a risk mgt framework based on the analysis; Some org's may accept known risks; Primary concern of an info security manager documenting a formal data retention policy is - correct answer Business Requirements! Best practices are useful, but not primary; Legislative or regulatory are only primary if they are part of the business requirments the maturity of an info security program is primarily the result of - correct answer An effective info security strategy; Strategy provides clear direction on how the organization will attain security outcomes and directed by senior mgt; Other note: Assess and analyzing risk is required to develop a strategy; provide info needed to develop it, but will not define the scope and charter of the security program; Security architecture is a part of a larger security plan Applicability statement is part of strategy implementation using ISO 27001 or 27002 after determining the scope & responsibilities of the program which of the following best supports the principle of security proportionality? - correct answer Asset Classification! Classification provides the basis for protecting resources in relation to their importance to the organization; More important assets get proportionally higher level of protection An Ownership schema is one step in achieving proportionality, but other steps must also occur Resource dependency analysis can reveal the level of protection afforded a particular system, but is unrelated to protection of assets! An organization's security awareness program should focus on which of the following? - correct answer An organizations security awareness program should focus on employee behavior and the consequences of both compliance and non compliance with security policy. It is essential to determine the forces that drive the business need for the information security program. Determining drivers is critical to - correct answer Establish the basis for the development of metrics! Determining drivers of the program establishes objectives and is essential to developing relevant metrics for the organization the Info security manager has determined tha a risk exceeds risk appetite, yet the manager does not mitigate the risk. What is the most likely reason that management would consider this course of action appropriate? - correct answer The risk falls within the risk tolerance level! Risk tolerance is the acceptable level of variation that management is willing to allow for any particular risk as the enterprise pursues its objectives.

Montrer plus Lire moins
Établissement
Cours

Aperçu du contenu

ISACA CISM 2-15 question & answer
2022
Questions - correct answer Answers and Explanations

Decisions regarding information security are best supported by - correct answer
effective metrics
effective metrics are essential to provide information needed to make decisions. Metrics
are quantifiable entity that allows the measurement of the achievement of a process
goal.

A project manager is developing a developer portal and request that the security
manager assign a public IP address so that it can be accessed by in house staff and by
external consultants outside the organization's local area network (LAN). What should
the security manager do first? - correct answer understand the business requirements
of the portal
you cannot make an uninformed decision. Learn and understand the business
requirement first! Vulernability accessment and Intrustion detection systems (IDS) are
subsequent tasks

Which of the following should be understood before defining risk management
strategies? - correct answer organizational objectives and risk appetite Analyze the
org's objectives and risk appetite, then define a risk mgt framework based on the
analysis; Some org's may accept known risks;

Primary concern of an info security manager documenting a formal data retention policy
is - correct answer Business Requirements!

Best practices are useful, but not primary; Legislative or regulatory are only primary if
they are part of the business requirments

the maturity of an info security program is primarily the result of - correct answer An
effective info security strategy;
Strategy provides clear direction on how the organization will attain security outcomes
and directed by senior mgt;
Other note:
Assess and analyzing risk is required to develop a strategy; provide info needed to
develop it, but will not define the scope and charter of the security program;
Security architecture is a part of a larger security plan
Applicability statement is part of strategy implementation using ISO 27001 or 27002
after determining the scope & responsibilities of the program

which of the following best supports the principle of security proportionality? - correct
answer Asset Classification!

École, étude et sujet

Cours

Infos sur le Document

Publié le
3 janvier 2024
Nombre de pages
4
Écrit en
2023/2024
Type
Examen
Contient
Questions et réponses

Sujets

$14.49
Accéder à l'intégralité du document:

Mauvais document ? Échangez-le gratuitement Dans les 14 jours suivant votre achat et avant le téléchargement, vous pouvez choisir un autre document. Vous pouvez simplement dépenser le montant à nouveau.
Rédigé par des étudiants ayant réussi
Disponible immédiatement après paiement
Lire en ligne ou en PDF


Document également disponible en groupe

Faites connaissance avec le vendeur

Seller avatar
Les scores de réputation sont basés sur le nombre de documents qu'un vendeur a vendus contre paiement ainsi que sur les avis qu'il a reçu pour ces documents. Il y a trois niveaux: Bronze, Argent et Or. Plus la réputation est bonne, plus vous pouvez faire confiance sur la qualité du travail des vendeurs.
THEEXCELLENCELIBRARY Harvard University
S'abonner Vous devez être connecté afin de suivre les étudiants ou les cours
Vendu
18
Membre depuis
2 année
Nombre de followers
6
Documents
2641
Dernière vente
2 mois de cela
THE EXCELLENCE LIBRARY

The Excellence Library Where Academic Success Begins. Welcome to The Excellence Library — your trusted marketplace for past and upcoming exam papers with verified answers, spanning all academic fields. Whether you're a med student, a future lawyer, a high schooler prepping for finals, or a researcher looking for model dissertations — we've got you covered. What We Offer Accurate & Complete Exam Papers From Medicine, Nursing, Law (Bar Exams), High School subjects, and more. Model Dissertations & Novels Top-tier academic references and full-text materials to guide your writing and study. Affordable & Fair Pricing Quality resources at a price that respects students' budgets. Why Choose Us? Thoroughly Reviewed Answers – Every paper includes clear, correct solutions. Massive Library – Thousands of documents, constantly updated. Academic Excellence, Delivered – We help you prepare smarter, not harder. Fast Delivery – Get what you need, when you need it. Our Goal To empower students and professionals by offering reliable, affordable academic materials — helping you succeed one paper at a time.

Lire la suite Lire moins
2.5

2 revues

5
0
4
0
3
1
2
1
1
0

Documents populaires

Récemment consulté par vous

Pourquoi les étudiants choisissent Stuvia

Créé par d'autres étudiants, vérifié par les avis

Une qualité sur laquelle compter : rédigé par des étudiants qui ont réussi et évalué par d'autres qui ont utilisé ce document.

Le document ne convient pas ? Choisis un autre document

Aucun souci ! Tu peux sélectionner directement un autre document qui correspond mieux à ce que tu cherches.

Paye comme tu veux, apprends aussitôt

Aucun abonnement, aucun engagement. Paye selon tes habitudes par carte de crédit et télécharge ton document PDF instantanément.

Student with book image

“Acheté, téléchargé et réussi. C'est aussi simple que ça.”

Alisha Student

Foire aux questions