Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 1Objective 4

Information Security Strategy Development CISM Practice Questions (Page 4)

Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.

40questions here
8free pages
12concepts
17%of the exam

Questions 16–20

  1. 16application · medium

    A university is planning its security strategy implementation. The strategy includes deploying a new identity management system, enhancing security awareness training, and establishing a 24/7 security operations center. The CISO must develop a resource plan. Which resource planning approach is most appropriate?

    Select an answer first
  2. 17foundation · easy

    What is the primary purpose of developing a phased roadmap for strategy implementation?

    Select an answer first
  3. 18foundation · easy

    What is the primary purpose of resource planning in information security strategy implementation?

    Select an answer first
  4. 19application · medium

    A manufacturing company is starting its annual security strategy review. The CISO has gathered data on current security incidents, control effectiveness, and compliance audit results. The next step in the strategy development process is to compare this current state against the desired future state defined by the board's risk appetite. Which activity best represents this next step?

    Select an answer first
  5. 20foundation · easy

    What is a key trigger for reviewing and updating the information security strategy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.