
Certified Information Security Manager
Domain 1Objective 6
Strategic Planning (Budgets, Resources, Business Case) CISM Practice Questions (Page 4)
Part of the Domain 1: Information Security Governance domain, which accounts for 17% of the CISM exam.
24questions here
5free pages
6concepts
17%of the exam
Questions 16–20
- 16
Which of the following is a valid criterion for prioritizing security projects?
Select an answer first - 17
A security manager must prioritize two projects: one that addresses a high-risk vulnerability in a critical system and another that improves the user experience of the security portal. The organization has limited resources. Which project should be prioritized?
Select an answer first - 18
In the context of information security governance, what is the primary purpose of strategic planning?
Select an answer first - 19
A security manager is developing a strategic plan for the next three years. The organization is planning to expand into new international markets, which will introduce new data privacy regulations. The security manager must ensure the security strategy supports this business expansion. Which action is most important?
Select an answer first - 20
A security manager is planning a major security initiative and must determine the resources required. Which resource type is most often underestimated in security projects?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISM” is a trademark of its owner, used for identification only.