Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 3Objective 1

Program Foundation and Governance CISM Practice Questions (Page 2)

Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.

32questions here
7free pages
9concepts
33%of the exam

Questions 6–10

  1. 6application · medium

    A startup company with 50 employees and a small security team wants to establish its first formal security program. The CISO has limited budget and staff and needs a framework that is practical to implement quickly while still providing a solid foundation. The company does not currently need formal certification. Which framework selection is most appropriate for this context?

    Select an answer first
  2. 7foundation · easy

    Which of the following is an example of an information asset?

    Select an answer first
  3. 8foundation · easy

    What is the first step in the process of developing a security policy?

    Select an answer first
  4. 9application · medium

    A financial institution has a policy that states 'All sensitive customer data must be encrypted at rest.' The CISO needs to ensure that IT staff know exactly how to implement this requirement for the various databases and file shares. Which document type should the CISO develop to provide the specific implementation steps?

    Select an answer first
  5. 10foundation · easy

    What is the primary purpose of classifying information assets?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.