
Certified Information Security Manager
Domain 1Objective 4
Information Security Strategy Development CISM Practice Questions (Page 1)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
40questions here
8free pages
12concepts
17%of the exam
Questions 1–5
- 1
A CISO is developing a resource plan for a new security strategy. The strategy includes three major initiatives: (1) deploying a zero-trust architecture, (2) establishing a security operations center (SOC), and (3) implementing a data classification program. The organization has a limited budget and a shortage of skilled security staff. The CISO must present a realistic resource plan to the board. Which approach is most appropriate?
Select an answer first - 2
An organization's security strategy was approved two years ago. Since then, the company has acquired a new subsidiary and the threat landscape has shifted significantly. The CISO must ensure the strategy remains relevant. Which action is most appropriate?
Select an answer first - 3
What is the primary purpose of communicating the security strategy to stakeholders?
Select an answer first - 4
What is the primary purpose of aligning the information security strategy with organizational goals and business requirements?
Select an answer first - 5
A logistics company has completed a gap analysis and identified the need to enhance its security operations center (SOC) capabilities. The CISO must formulate strategic objectives and initiatives. Which formulation best defines a strategic objective with associated initiatives?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.