
Certified Information Security Manager
Domain 2Objective 5
Risk and Control Ownership CISM Practice Questions (Page 2)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
24questions here
5free pages
6concepts
20%of the exam
Questions 6–10
- 6
A multinational corporation has a risk owner for a critical data breach risk. The risk owner is the head of the IT department. The risk is related to a business process owned by the marketing department. The marketing department has implemented controls, but the risk owner has no authority over the marketing department's budget or processes. The risk remains high. What is the most effective solution?
Select an answer first - 7
How does control ownership integrate into the risk management lifecycle after a risk treatment decision is made?
Select an answer first - 8
A project manager is responsible for implementing a new security control. The project manager has completed the implementation and handed the control over to the IT operations team. The IT operations team is now responsible for maintaining the control. Who is accountable for the control's ongoing effectiveness?
Select an answer first - 9
A risk owner delegates the daily monitoring of a control to a system administrator. Which statement is true regarding accountability and responsibility in this scenario?
Select an answer first - 10
A manufacturing company has a risk owner for its supply-chain disruption risk. The risk owner has delegated the day-to-day monitoring of supplier security assessments to a junior analyst. The analyst performs the assessments and reports findings. A significant supplier risk is missed, and the company suffers a disruption. Who is ultimately accountable for the failure to manage this risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.