Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Security Manager

Domain 2Objective 5

Risk and Control Ownership CISM Practice Questions (Page 4)

Part of the Domain 2: Information Security Risk Management domain, which accounts for 20% of the CISM exam.

24questions here
5free pages
6concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A new risk has been identified in a company's customer data handling process. The risk owner has been assigned, but the risk owner is unsure which controls are already in place. What should the risk owner do first?

    Select an answer first
  2. 17foundation · easy

    Which factor is most important when assigning control ownership?

    Select an answer first
  3. 18foundation · easy

    Which type of information should a control owner include when reporting on control effectiveness to stakeholders?

    Select an answer first
  4. 19application · medium

    A risk owner needs to report the status of a high-risk item to the executive committee. The risk has been mitigated, but residual risk remains. What is the most appropriate information for the risk owner to include in the report?

    Select an answer first
  5. 20expert · hard

    A company is implementing a new risk management framework. The CISO must assign ownership for a risk that spans multiple business units. The risk affects the finance, HR, and IT departments. Which approach is most appropriate for assigning ownership?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.