• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 7 pages
Exam (elaborations)

CISM CH1 Practice Questions and Answers Rated A

Document preview thumbnail
Preview 2 out of 7 pages

CISM CH1 Practice Questions and Answers Rated A

Content preview

CISM CH1 Practice Questions and Answers Rated A




CH1: What are the 6 outcomes of Security Governance? - ANSWER-1. Strategic
Alignment
2. Risk Management
3. Value Delivery
4. Resource Optimization
5. Performance Measurement
6 Assurance Process Integration

CH1: A security strategy is important for an organization PRIMARILY because it:

A. provides a basis for determining the best logical security architecture for the
organization.
B. provides the approach to acheiving the outcomes management wants.
C. Provides users guidance on how to operate securely in everyday tasks.
D. helps IS auditors ensure compliance. - ANSWER-B.

A security strategy will define the approach to achieving the security program
outcomes management wants. It shouls also be a statement of how security aligns
with and supports business objectives, and it provides the basis for good security
governance.

CH1: Which of the following is the MOST important reason to provide effective
communication about information security?

A. It makes information security more palatable to resistant employees.
B. It mitigates the weakest link in the information security landscape.
C. It informs business units about the information security strategy.
D. It helps the organization conform to regulatory information security
requirements. - ANSWER-B.

Security failures are, in the majority of instances, directly attributable to lack of
awareness or failure of employees to follow policies or procedures. Communication
is important to ensure continued awareness of security policies and procedures
among staff and business partners.

CH1: Which of the following approaches BEST helps the information security
manager achieve compliance with various regulatory requirements?

A. Rely on corporate counsel to advise which regulations are the most relevant.
B. Stay current with all relevant regulations and request legal interpretation.

, C. Involve all impacted departments and treat regulations as just another risk.
D. Ignore many of the regulations that have no penalties. - ANSWER-C.

Departments such as HR, finance, and legal are most oftensubject to new
regulations and therefore must be involved in determining how best to meet the
existing and emerging requirements and would be most aware of these regulations.
Treating regulations like a risk puts them in the proper perspective and
mechanisms to deal with them should already exist.

CH1: The MOST important consideration in developing security policies is that:

A. they are based on a threat profile.
B. they are complete and no detail is left out.
C. management signs off on them
D. all employees read and understand them. - ANSWER-A.

The basis for developing relevant security policies is addressing viable threats to
the organization, prioritized by the likelihood of occurrence and potential impact on
the business. Strictest policies apply to the areas of greatest business value for
proportional maintenance.

CH1: The PRIMARY security objective in creating good procedures is:

A. to make sure they work as intended.
B. that they are unambiguous and meet the standards.
C. that they are written in plain language and widely distributed.
D. that compliance is monitored. - ANSWER-B.

All are important, but the first criterion must be to ensure there is no ambiguity in
the procedures and that from a security perspective, they meet the applicable
standards and comply with the policy.

CH1: Which of the following MOST helps ensure that assignment of roles and
responsibilities is effective:

A. Senior management is in support of the assignments.
B. The assignments are consistent with existing proficiencies.
C. The assignments are mapped to required skills.
D. The assignments are given on a voluntary basis. - ANSWER-B.

The level of effectiveness of employees will be determined by their existing
knowledge and capabilities/proficiences.

CH1: Which of the following benefits is the MOST important to an organization with
effective information security governance?

A. Maintaining appropriate regulatory compliance
B. Ensuring disruptions are within acceptable levels.

Document information

Uploaded on
August 31, 2026
Number of pages
7
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CLOUNDLite
3.9
(128)
Sold
659
Followers
389
Items
12325
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions