
Certified Information Security Manager
Domain 1Objective 5
Information Governance Frameworks and Standards CISM Practice Questions (Page 4)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
21questions here
5free pages
4concepts
17%of the exam
Questions 16–20
- 16
A company is required to implement a set of security controls that are prioritized based on the most common cyber attacks. The CISO wants to use a framework that is practical and provides a clear roadmap for implementation. Which framework should the CISO choose?
Select an answer first - 17
A mid-sized company is considering adopting a governance framework but has limited resources and needs to quickly improve its security posture. The CISO wants a framework that is practical, prioritized, and widely recognized. Which framework would best meet these needs?
Select an answer first - 18
A public sector organization is required to align its information security program with a national cybersecurity framework. The organization also wants to ensure that its governance structure supports accountability and continuous improvement. Which component of an information governance framework is most important for achieving continuous improvement?
Select an answer first - 19
Which of the following is a key information security standard that provides requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS)?
Select an answer first - 20
A retail company is implementing an information governance framework to improve data classification and handling. The CISO wants to ensure that the framework is integrated with the company's existing enterprise risk management (ERM) process. Which component of the framework is most critical for this integration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.