Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 2Objective 5

Risk and Control Ownership CISM Practice Questions (Page 3)

Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.

24questions here
5free pages
6concepts
20%of the exam

Questions 11–15

  1. 11foundation · easy

    In an organization's information security risk management program, which individual is ultimately accountable for ensuring that a specific risk is managed to an acceptable level?

    Select an answer first
  2. 12foundation · easy

    Which activity is most directly associated with a control owner's role?

    Select an answer first
  3. 13application · medium

    A healthcare organization has implemented a new access-control system. The IT operations manager is responsible for configuring user permissions and maintaining the system daily. The compliance officer is accountable for ensuring the system meets regulatory requirements. During an audit, a reviewer asks who is responsible for the control. Which individual should the reviewer identify as the control owner?

    Select an answer first
  4. 14foundation · easy

    In the context of risk and control ownership, how does accountability differ from responsibility?

    Select an answer first
  5. 15foundation · easy

    What is the first step in assigning risk ownership to an appropriate individual?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.