
Certified Information Security Manager
Domain 3Objective 1
Program Foundation and Governance CISM Practice Questions (Page 5)
Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.
32questions here
7free pages
9concepts
33%of the exam
Questions 21–25
- 21
A large organization is implementing a new security policy that requires multi-factor authentication (MFA) for all system access. The CISO must ensure the policy is effectively implemented across the organization. The organization has a mix of technical and non-technical employees, and some legacy systems do not support MFA. Which implementation approach is most effective?
Select an answer first - 22
Who is typically responsible for determining the classification of an information asset?
Select an answer first - 23
A government contractor is required to implement a security program that aligns with NIST SP 800-171 for controlled unclassified information (CUI). The CISO is evaluating whether to adopt a broader framework to guide the overall program. The organization also needs to demonstrate compliance to auditors and manage security across multiple business units. Which framework adoption strategy is most appropriate?
Select an answer first - 24
A healthcare organization is implementing a data classification scheme. The compliance officer wants to ensure that protected health information (PHI) is handled with the highest level of protection, while internal marketing materials receive minimal controls. The CISO must define classification levels and criteria that align with regulatory requirements and operational needs. Which classification approach best meets these requirements?
Select an answer first - 25
A retail company is deciding between adopting the NIST Cybersecurity Framework (CSF) and ISO/IEC 27001. The company has a strong technical security posture but lacks formal governance processes. The CISO needs to improve governance while maintaining flexibility to adapt to changing business needs. The company is not required to obtain certification but wants to demonstrate due diligence to its board and customers. Which framework adoption is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.