
Certified Information Security Manager
Domain 2Objective 5
Risk and Control Ownership CISM Practice Questions (Page 4)
Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.
24questions here
5free pages
6concepts
20%of the exam
Questions 16–20
- 16
A new risk has been identified in a company's customer data handling process. The risk owner has been assigned, but the risk owner is unsure which controls are already in place. What should the risk owner do first?
Select an answer first - 17
Which factor is most important when assigning control ownership?
Select an answer first - 18
Which type of information should a control owner include when reporting on control effectiveness to stakeholders?
Select an answer first - 19
A risk owner needs to report the status of a high-risk item to the executive committee. The risk has been mitigated, but residual risk remains. What is the most appropriate information for the risk owner to include in the report?
Select an answer first - 20
A company is implementing a new risk management framework. The CISO must assign ownership for a risk that spans multiple business units. The risk affects the finance, HR, and IT departments. Which approach is most appropriate for assigning ownership?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.