Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 1Objective 1

Organizational Culture CISM Practice Questions (Page 4)

Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.

27questions here
6free pages
4concepts
17%of the exam

Questions 16–20

  1. 16foundation · easy

    Which statement best defines organizational culture in the context of information security governance?

    Select an answer first
  2. 17application · medium

    A security manager is evaluating why a new security policy is being ignored by employees. The policy requires two-factor authentication for all remote access. Which cultural factor is most likely contributing to the resistance?

    Select an answer first
  3. 18application · medium

    A company's governance objectives emphasize data protection and regulatory compliance, but the prevailing culture rewards 'getting things done' over following processes. The security manager wants to align the culture with governance objectives. What is the most effective first step?

    Select an answer first
  4. 19application · medium

    A company's governance objectives emphasize continuous improvement, but the culture is risk-averse and resistant to change. The security manager wants to align the culture with the objective of continuous improvement in security practices. What is the best approach?

    Select an answer first
  5. 20application · medium

    A company wants to embed security awareness into its daily operations. The security team has limited budget and resources. Which initiative is most cost-effective and sustainable?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.