
Certified Information Security Manager
Domain 3Objective 1
Program Foundation and Governance CISM Practice Questions (Page 6)
Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.
32questions here
7free pages
9concepts
33%of the exam
Questions 26–30
- 26
Why is it important to regularly review and update security policies?
Select an answer first - 27
A software development company has classified its source code as 'Internal'. The development team lead is responsible for the code, while the DevOps team manages the code repository. A new developer joins the team and needs access to the repository. According to the principles of asset ownership and handling, who should authorize the new developer's access?
Select an answer first - 28
What is the primary difference between a security policy and a security procedure?
Select an answer first - 29
Which of the following BEST describes the primary purpose of identifying and aligning security program resources with organizational needs?
Select an answer first - 30
When selecting a security framework, what is an important factor to consider?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.