
Certified Information Security Manager
Domain 1Objective 5
Information Governance Frameworks and Standards CISM Practice Questions (Page 2)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
21questions here
5free pages
4concepts
17%of the exam
Questions 6–10
- 6
A company is adopting a new governance framework. The CISO must decide between implementing ISO/IEC 27001 or the NIST Cybersecurity Framework (CSF). The company has a mature risk management process and wants to avoid duplicating efforts. Which approach best leverages the existing risk management process?
Select an answer first - 7
Which of the following best describes the role of NIST frameworks and standards in information security governance?
Select an answer first - 8
When selecting a governance framework for an organization, which of the following should be the primary consideration?
Select an answer first - 9
A large enterprise is implementing a new information governance framework. The board of directors is concerned about the cost and effort of the implementation and wants to ensure that the framework delivers measurable value. The CISO must align the framework with the enterprise's strategic objectives. Which approach best ensures that the framework delivers value and aligns with enterprise governance?
Select an answer first - 10
Which of the following is a typical component of an information governance framework?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.