
Certified Information Security Manager
Domain 1Objective 3
Organizational Structures, Roles and Responsibilities CISM Practice Questions (Page 1)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
22questions here
5free pages
5concepts
17%of the exam
Questions 1–5
- 1
A financial services firm operates in multiple countries with strict local data protection regulations. The firm wants to maintain consistent security policies globally while allowing local teams to implement controls that meet regional legal requirements. Which organizational structure is most appropriate?
Select an answer first - 2
In a large organization, the same individual is responsible for both approving and implementing changes to firewall rules. Which risk does this create, and what is the best mitigation?
Select an answer first - 3
What is the primary purpose of a security steering committee in information security governance?
Select an answer first - 4
Which organizational structure for information security governance is characterized by a central security team that sets standards and provides oversight while business units retain some implementation flexibility?
Select an answer first - 5
A company is considering moving the CISO reporting line from the CIO to the Chief Risk Officer (CRO). What is the primary advantage of this change?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.