
Certified Information Security Manager
Domain 3Objective 1
Program Foundation and Governance CISM Practice Questions (Page 7)
Part of the Domain 3: Information Security Program domain, which accounts for 33% of the CISM exam.
32questions here
7free pages
9concepts
33%of the exam
Questions 31–32
- 31
A mid-sized financial services firm is adopting the NIST Cybersecurity Framework (CSF) to mature its security program. The CISO has been given a flat budget for the next fiscal year and must allocate resources to close the highest-priority gaps identified in a current-state assessment. The assessment shows that the organization has strong technical controls but weak governance processes, including no formal risk appetite statement and inconsistent policy enforcement. Which resource allocation should the CISO prioritize?
Select an answer first - 32
A university is creating an information asset inventory. The CISO wants to ensure that the inventory is useful for risk management and that assets are properly protected. The university has research data, student records, administrative systems, and public website content. Which action is most important to ensure the inventory supports risk-based decisions?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CISM
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.