CISM CH1 Practice Questions and Answers Rated A
CH1: What are the 6 outcomes of Security Governance? - ANSWER-1. Strategic
Alignment
2. Risk Management
3. Value Delivery
4. Resource Optimization
5. Performance Measurement
6 Assurance Process Integration
CH1: A security strategy is important for an organization PRIMARILY because it:
A. provides a basis for determining the best logical security architecture for the
organization.
B. provides the approach to acheiving the outcomes management wants.
C. Provides users guidance on how to operate securely in everyday tasks.
D. helps IS auditors ensure compliance. - ANSWER-B.
A security strategy will define the approach to achieving the security program
outcomes management wants. It shouls also be a statement of how security aligns
with and supports business objectives, and it provides the basis for good security
governance.
CH1: Which of the following is the MOST important reason to provide effective
communication about information security?
A. It makes information security more palatable to resistant employees.
B. It mitigates the weakest link in the information security landscape.
C. It informs business units about the information security strategy.
D. It helps the organization conform to regulatory information security
requirements. - ANSWER-B.
Security failures are, in the majority of instances, directly attributable to lack of
awareness or failure of employees to follow policies or procedures. Communication
is important to ensure continued awareness of security policies and procedures
among staff and business partners.
CH1: Which of the following approaches BEST helps the information security
manager achieve compliance with various regulatory requirements?
A. Rely on corporate counsel to advise which regulations are the most relevant.
B. Stay current with all relevant regulations and request legal interpretation.
, C. Involve all impacted departments and treat regulations as just another risk.
D. Ignore many of the regulations that have no penalties. - ANSWER-C.
Departments such as HR, finance, and legal are most oftensubject to new
regulations and therefore must be involved in determining how best to meet the
existing and emerging requirements and would be most aware of these regulations.
Treating regulations like a risk puts them in the proper perspective and
mechanisms to deal with them should already exist.
CH1: The MOST important consideration in developing security policies is that:
A. they are based on a threat profile.
B. they are complete and no detail is left out.
C. management signs off on them
D. all employees read and understand them. - ANSWER-A.
The basis for developing relevant security policies is addressing viable threats to
the organization, prioritized by the likelihood of occurrence and potential impact on
the business. Strictest policies apply to the areas of greatest business value for
proportional maintenance.
CH1: The PRIMARY security objective in creating good procedures is:
A. to make sure they work as intended.
B. that they are unambiguous and meet the standards.
C. that they are written in plain language and widely distributed.
D. that compliance is monitored. - ANSWER-B.
All are important, but the first criterion must be to ensure there is no ambiguity in
the procedures and that from a security perspective, they meet the applicable
standards and comply with the policy.
CH1: Which of the following MOST helps ensure that assignment of roles and
responsibilities is effective:
A. Senior management is in support of the assignments.
B. The assignments are consistent with existing proficiencies.
C. The assignments are mapped to required skills.
D. The assignments are given on a voluntary basis. - ANSWER-B.
The level of effectiveness of employees will be determined by their existing
knowledge and capabilities/proficiences.
CH1: Which of the following benefits is the MOST important to an organization with
effective information security governance?
A. Maintaining appropriate regulatory compliance
B. Ensuring disruptions are within acceptable levels.
CH1: What are the 6 outcomes of Security Governance? - ANSWER-1. Strategic
Alignment
2. Risk Management
3. Value Delivery
4. Resource Optimization
5. Performance Measurement
6 Assurance Process Integration
CH1: A security strategy is important for an organization PRIMARILY because it:
A. provides a basis for determining the best logical security architecture for the
organization.
B. provides the approach to acheiving the outcomes management wants.
C. Provides users guidance on how to operate securely in everyday tasks.
D. helps IS auditors ensure compliance. - ANSWER-B.
A security strategy will define the approach to achieving the security program
outcomes management wants. It shouls also be a statement of how security aligns
with and supports business objectives, and it provides the basis for good security
governance.
CH1: Which of the following is the MOST important reason to provide effective
communication about information security?
A. It makes information security more palatable to resistant employees.
B. It mitigates the weakest link in the information security landscape.
C. It informs business units about the information security strategy.
D. It helps the organization conform to regulatory information security
requirements. - ANSWER-B.
Security failures are, in the majority of instances, directly attributable to lack of
awareness or failure of employees to follow policies or procedures. Communication
is important to ensure continued awareness of security policies and procedures
among staff and business partners.
CH1: Which of the following approaches BEST helps the information security
manager achieve compliance with various regulatory requirements?
A. Rely on corporate counsel to advise which regulations are the most relevant.
B. Stay current with all relevant regulations and request legal interpretation.
, C. Involve all impacted departments and treat regulations as just another risk.
D. Ignore many of the regulations that have no penalties. - ANSWER-C.
Departments such as HR, finance, and legal are most oftensubject to new
regulations and therefore must be involved in determining how best to meet the
existing and emerging requirements and would be most aware of these regulations.
Treating regulations like a risk puts them in the proper perspective and
mechanisms to deal with them should already exist.
CH1: The MOST important consideration in developing security policies is that:
A. they are based on a threat profile.
B. they are complete and no detail is left out.
C. management signs off on them
D. all employees read and understand them. - ANSWER-A.
The basis for developing relevant security policies is addressing viable threats to
the organization, prioritized by the likelihood of occurrence and potential impact on
the business. Strictest policies apply to the areas of greatest business value for
proportional maintenance.
CH1: The PRIMARY security objective in creating good procedures is:
A. to make sure they work as intended.
B. that they are unambiguous and meet the standards.
C. that they are written in plain language and widely distributed.
D. that compliance is monitored. - ANSWER-B.
All are important, but the first criterion must be to ensure there is no ambiguity in
the procedures and that from a security perspective, they meet the applicable
standards and comply with the policy.
CH1: Which of the following MOST helps ensure that assignment of roles and
responsibilities is effective:
A. Senior management is in support of the assignments.
B. The assignments are consistent with existing proficiencies.
C. The assignments are mapped to required skills.
D. The assignments are given on a voluntary basis. - ANSWER-B.
The level of effectiveness of employees will be determined by their existing
knowledge and capabilities/proficiences.
CH1: Which of the following benefits is the MOST important to an organization with
effective information security governance?
A. Maintaining appropriate regulatory compliance
B. Ensuring disruptions are within acceptable levels.