
Certified Information Security Manager
Domain 1Objective 5
Information Governance Frameworks and Standards CISM Practice Questions (Page 3)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
21questions here
5free pages
4concepts
17%of the exam
Questions 11–15
- 11
A government contractor must comply with NIST SP 800-171 for protecting controlled unclassified information (CUI). The company also wants to adopt a broader governance framework to manage its overall security program. Which combination of standards would best meet both requirements?
Select an answer first - 12
A company is adopting a governance framework and wants to ensure that it can measure the effectiveness of its security program. The CISO wants to use a framework that includes maturity models and capability levels. Which framework best supports this need?
Select an answer first - 13
A multinational corporation is adopting a new information security framework. The CISO must choose between ISO/IEC 27001 and NIST Cybersecurity Framework (CSF). The company operates in a highly regulated industry and needs to demonstrate compliance to multiple regulators. Which factor should most influence the decision?
Select an answer first - 14
How does an information governance framework typically integrate with enterprise risk management (ERM)?
Select an answer first - 15
A company is implementing an information governance framework and wants to ensure that it addresses the full lifecycle of information, from creation to disposal. Which component of the framework is most relevant to this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.