Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 3Objective 1

Program Foundation and Governance CISM Practice Questions (Page 3)

Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.

32questions here
7free pages
9concepts
33%of the exam

Questions 11–15

  1. 11application · medium

    A multinational retail company is building an information asset inventory. The CISO wants to ensure that all assets are identified and that the inventory supports downstream classification and protection decisions. The company operates both on-premises data centers and multiple cloud environments, and it has a mix of custom applications, SaaS services, and employee-owned devices used under BYOD. Which approach best ensures comprehensive asset identification?

    Select an answer first
  2. 12expert · hard

    A multinational corporation is considering adopting ISO/IEC 27001 for its information security management system. The company has operations in 30 countries, each with its own regulatory requirements. The CISO must decide whether to pursue certification for the entire organization or for specific business units. The company has a mature security program but has never pursued formal certification. Which approach best balances certification benefits with implementation effort?

    Select an answer first
  3. 13foundation · easy

    What is the primary role of a custodian in the handling of an information asset?

    Select an answer first
  4. 14expert · hard

    A manufacturing company is establishing a security program and needs to determine the appropriate resources. The company has a small security team and a limited budget. The CISO must decide whether to build an in-house security operations center (SOC) or use a managed security service provider (MSSP). The company has a high need for 24/7 monitoring and incident response, but also wants to maintain control over its security operations. Which approach best balances these needs?

    Select an answer first
  5. 15application · medium

    A global company is updating its information security policy to address new data privacy regulations. The CISO has drafted the policy and needs to ensure it is properly approved and communicated. The company operates in multiple countries with different legal requirements. Which step is most important for the CISO to take before finalizing the policy?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.