
Certified Information Security Manager
Domain 1Objective 3
Organizational Structures, Roles and Responsibilities CISM Practice Questions (Page 4)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
22questions here
5free pages
5concepts
17%of the exam
Questions 16–20
- 16
A global organization is redesigning its security governance. The board wants consistent risk reporting, but regional business units require agility to respond to local threats. The CISO is concerned about maintaining segregation of duties across regions. Which approach best balances these competing needs?
Select an answer first - 17
A security steering committee is struggling to make decisions because the CISO and the business unit leaders have conflicting priorities. The CISO wants to implement strict controls, while business leaders want to minimize disruption. Which action would best help the committee resolve this conflict and make effective decisions?
Select an answer first - 18
Which of the following is typically a member of a security steering committee?
Select an answer first - 19
What is a potential disadvantage of the information security function reporting to the CIO?
Select an answer first - 20
Which scenario best demonstrates the principle of segregation of duties in information security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.