
Certified Information Security Manager
Domain 1Objective 4
Information Security Strategy Development CISM Practice Questions (Page 5)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
40questions here
8free pages
12concepts
17%of the exam
Questions 21–25
- 21
A CISO has developed a roadmap for a security strategy with three phases. Phase 1 includes implementing multi-factor authentication (MFA) and patching critical vulnerabilities. Phase 2 includes deploying a data loss prevention (DLP) program. Phase 3 includes establishing a formal security awareness program. The CISO must present this roadmap to the board, which is concerned about the time to value. Which adjustment to the roadmap would best address the board's concern?
Select an answer first - 22
A CISO has developed a new security strategy that requires significant changes to business processes and additional investment. To gain buy-in, the CISO must communicate the strategy to key stakeholders. Which communication approach is most effective for obtaining support from the board of directors?
Select an answer first - 23
What is the primary purpose of a gap analysis in information security strategy development?
Select an answer first - 24
Why is it important to establish a process for periodic review and update of the security strategy?
Select an answer first - 25
A CISO has finalized a three-year security strategy and needs to integrate it into the organization's governance processes. Which action best ensures the strategy is formally approved and embedded in governance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.