

[Apr 09, 2022] Valid CISM Test Answers & CISM Exam PDF
Valid Isaca Certification CISM Dumps Ensure Your Passing
Besides that, this section will test your skills in the following:
- To evaluate the effectiveness and efficiency of information security management, one should know how to monitor and analyze program management and operational metrics;
- Establishing a program for information security awareness and training for the effectiveness of security statistics.
- Maintaining and establishing the information security program in line with the information security strategy;
- To ensure whether the information security program adds value and protects the business, one should know how to align the information security program with the operational objectives of other functions of the business;
ISACA Information Security Manager Exam Syllabus Topics:
| Topic | Details | Weights |
|---|
| Information Security Program Development and Management | -Develop and maintain an information security program that identifies, manages and protects the organization’s assets while aligning to information security strategy and business goals, thereby supporting an effective security posture. Task Statements - Establish and/or maintain the information security program in alignment with the information security strategy.
- Align the information security program with the operational objectives of other business functions (e.g., human resources [HR], accounting, procurement and IT) to ensure that the information security program adds value to and protects the business.
- Identify, acquire and manage requirements for internal and external resources to execute the information security program.
- Establish and maintain information security processes and resources (including people and technologies) to execute the information security program in alignment with the organization’s business goals.
- Establish, communicate and maintain organizational information security standards, guidelines, procedures and other documentation to guide and enforce compliance with information security policies.
- Establish, promote and maintain a program for information security awareness and training to foster an effective security culture.
- Integrate information security requirements into organizational processes (e.g., change control, mergers and acquisitions, system development, business continuity, disaster recovery) to maintain the organization’s security strategy.
- Integrate information security requirements into contracts and activities of third parties (e.g., joint ventures, outsourced providers, business partners, customers) and monitor adherence to established requirements in order to maintain the organization’s security strategy.
- Establish, monitor and analyze program management and operational metrics to evaluate the effectiveness and efficiency of the information security program.
- Compile and present reports to key stakeholders on the activities, trends and overall effectiveness of the IS program and the underlying business processes in order to communicate security performance.
Knowledge Statements - Knowledge of methods to align information security program requirements with those of other business functions
- Knowledge of methods to identify, acquire, manage and define requirements for internal and external resources
- Knowledge of current and emerging information security technologies and underlying concepts
- Knowledge of methods to design and implement information security controls
- Knowledge of information security processes and resources (including people and technologies) in alignment with the organization’s business goals and methods to apply them
- Knowledge of methods to develop information security standards, procedures and guidelines
- Knowledge of internationally recognized regulations, standards, frameworks and best practices related to information security program development and management
- Knowledge of methods to implement and communicate information security policies, standards, procedures and guidelines
- Knowledge of training, certifications and skill set development for information security personnel
- Knowledge of methods to establish and maintain effective information security awareness and training programs
- Knowledge of methods to integrate information security requirements into organizational processes (e.g., access management, change management, audit processes)
- Knowledge of methods to incorporate information security requirements into contracts, agreements and third-party management processes
- Knowledge of methods to monitor and review contracts and agreements with third parties and associated change processes as required
- Knowledge of methods to design, implement and report operational information security metrics
- Knowledge of methods for testing the effectiveness and efficiency of information security controls
- Knowledge of techniques to communicate information security program status to key stakeholders
| 27% |
| Information Risk Management | -Manage information risk to an acceptable level based on risk appetite in order to meet organizational goals and objectives. Task Statements - Establish and/or maintain a process for information asset classification to ensure that measures taken to protect assets are proportional to their business value.
- Identify legal, regulatory, organizational and other applicable requirements to manage the risk of noncompliance to acceptable levels.
- Ensure that risk assessments, vulnerability assessments and threat analyses are conducted consistently, at appropriate times, and to identify and assess risk to the organization’s information.
- Identify, recommend or implement appropriate risk treatment/response options to manage risk to acceptable levels based on organizational risk appetite.
- Determine whether information security controls are appropriate and effectively manage risk to an acceptable level.
- Facilitate the integration of information risk management into business and IT processes (e.g., systems development, procurement, project management) to enable a consistent and comprehensive information risk management program across the organization.
- Monitor for internal and external factors (e.g., key risk indicators [KRIs], threat landscape, geopolitical, regulatory change) that may require reassessment of risk to ensure that changes to existing, or new, risk scenarios are identified and managed appropriately.
- Report noncompliance and other changes in information risk to facilitate the risk management decision-making process.
- Ensure that information security risk is reported to senior management to support an understanding of potential impact on the organizational goals and objectives.
Knowledge Statements - Knowledge of methods to establish an information asset classification model consistent with business objectives.
- Knowledge of considerations for assigning ownership of information assets and risk.
- Knowledge of methods to identify and evaluate the impact of internal or external events on information assets and the business.
- Knowledge of methods used to monitor internal or external risk factors.
- Knowledge of information asset valuation methodologies.
- Knowledge of legal, regulatory, organizational and other requirements related to information security.
- Knowledge of reputable, reliable and timely sources of information regarding emerging information security threats and vulnerabilities.
- Knowledge of events that may require risk reassessments and changes to information security program elements.
- Knowledge of information threats, vulnerabilities and exposures and their evolving nature.
- Knowledge of risk assessment and analysis methodologies.
- Knowledge of methods used to prioritize risk scenarios and risk treatment/response options.
- Knowledge of risk reporting requirements (e.g., frequency, audience, content).
- Knowledge of risk treatment/response options (avoid, mitigate, accept or transfer) and methods to apply them.
- Knowledge of control baselines and standards and their relationships to risk assessments.
- Knowledge of information security controls and the methods to analyze their effectiveness.
- Knowledge of gap analysis techniques as related to information security.
- Knowledge of techniques for integrating information security risk management into business and IT processes.
- Knowledge of compliance reporting requirements and processes.
- Knowledge of cost/benefit analysis to assess risk treatment options.
| 30% |
| Information Security Governance | -Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with organizational goals and objectives. Task Statements - Establish and/or maintain an information security strategy in alignment with organizational goals and objectives to guide the establishment and/or ongoing management of the information security program.
- Establish and/or maintain an information security governance framework to guide activities that support the information security strategy.
- Integrate information security governance into corporate governance to ensure that organizational goals and objectives are supported by the information security program.
- Establish and maintain information security policies to guide the development of standards, procedures and guidelines in alignment with enterprise goals and objectives.
- Develop business cases to support investments in information security.
- Identify internal and external influences to the organization (e.g., emerging technologies, social media, business environment, risk tolerance, regulatory requirements, third-party considerations, threat landscape) to ensure that these factors are continually addressed by the information security strategy.
- Gain ongoing commitment from senior leadership and other stakeholders to support the successful implementation of the information security strategy.
- Define, communicate, and monitor information security responsibilities throughout the organization (e.g., data owners, data custodians, end-users, privileged or high-risk users) and lines of authority.
- Establish, monitor, evaluate and report key information security metrics to provide management with accurate and meaningful information regarding the effectiveness of the information security strategy.
Knowledge Statements - Knowledge of techniques used to develop an information security strategy (e.g., SWOT [strengths, weaknesses, opportunities, threats] analysis, gap analysis, threat research)
- Knowledge of the relationship of information security to business goals, objectives, functions, processes and practices.
- Knowledge of available information security governance frameworks.
- Knowledge of globally recognized standards, frameworks and industry best practices related to information security governance and strategy development.
- Knowledge of the fundamental concepts of governance and how they relate to information security.
- Knowledge of methods to assess, plan, design and implement an information security governance framework.
- Knowledge of methods to integrate information security governance into corporate governance.
- Knowledge of contributing factors and parameters (e.g., organizational structure and culture, tone at the top, regulations) for information security policy development
- Knowledge of content in, and techniques to develop, business cases.
- Knowledge of strategic budgetary planning and reporting methods.
- Knowledge of the internal and external influences to the organization (e.g., emerging technologies, social media, business environment, risk tolerance, regulatory requirements, third-party considerations, threat landscape) and how they impact the information security strategy.
- Knowledge of key information needed to obtain commitment from senior leadership and support from other stakeholders (e.g., how information security supports organizational goals and objectives, criteria for determining successful implementation, business impact).
- Knowledge of methods and considerations for communicating with senior leadership and other stakeholders (e.g., organizational culture, channels of communication, highlighting essential aspects of information security).
- Knowledge of roles and responsibilities of the information security manager.
- Knowledge of organizational structures, lines of authority and escalation points.
- Knowledge of information security responsibilities of staff across the organization (e.g., data owners, end-users, privileged or high-risk users)
- Knowledge of processes to monitor performance of information security responsibilities.
- Knowledge of methods to establish new, or utilize existing, reporting and communication channels throughout an organization.
- Knowledge of methods to select, implement and interpret key information security metrics (e.g., key performance indicators [KPIs] or key risk indicators [KRIs]).
| 24% |
| Information Security Incident Management | -Plan, establish and manage the capability to detect, investigate, respond to and recover from information security incidents to minimize business impact. Task Statements - Establish and maintain an organizational definition of, and severity hierarchy for, information security incidents to allow accurate classification and categorization of and response to incidents.
- Establish and maintain an incident response plan to ensure an effective and timely response to information security incidents.
- Develop and implement processes to ensure the timely identification of information security incidents that could impact the business.
- Establish and maintain processes to investigate and document information security incidents in order to determine the appropriate response and cause while adhering to legal, regulatory and organizational requirements.
- Establish and maintain incident notification and escalation processes to ensure that the appropriate stakeholders are involved in incident response management.
- Organize, train and equip incident response teams to respond to information security incidents in an effective and timely manner.
- Test, review and revise (as applicable) the incident response plan periodically to ensure an effective response to information security incidents and to improve response capabilities.
- Establish and maintain communication plans and processes to manage communication with internal and external entities.
- Conduct post-incident reviews to determine the root cause of information security incidents, develop corrective actions, reassess risk, evaluate response effectiveness and take appropriate remedial actions.
- Establish and maintain integration among the incident response plan, business continuity plan and disaster recovery plan.
Knowledge Statements - Knowledge of incident management concepts and practices.
- Knowledge of the components of an incident response plan.
- Knowledge of business continuity planning (BCP) and disaster recovery planning (DRP) and their relationship to the incident response plan.
- Knowledge of incident classification/categorization methods.
- Knowledge of incident containment methods to minimize adverse operational impact.
- Knowledge of notification and escalation processes.
- Knowledge of the roles and responsibilities in identifying and managing information security incidents.
- Knowledge of the types and sources of training, tools and equipment required to adequately equip incident response teams.
- Knowledge of forensic requirements and capabilities for collecting, preserving and presenting evidence (e.g., admissibility, quality and completeness of evidence, chain of custody).
- Knowledge of internal and external incident reporting requirements and procedures.
- Knowledge of post-incident review practices and investigative methods to identify root causes and determine corrective actions.
- Knowledge of techniques to quantify damages, costs and other business impacts arising from information security incidents.
- Knowledge of technologies and processes to detect, log, analyze and document information security events.
- Knowledge of internal and external resources available to investigate information security incidents.
- Knowledge of methods to identify and quantify the potential impact of changes made to the operating environment during the incident response process.
- Knowledge of techniques to test the incident response plan.
- Knowledge of applicable regulatory, legal and organization requirements.
- Knowledge of key indicators/metrics to evaluate the effectiveness of the incident response plan.
| 19% |
NEW QUESTION 506
A border router should be placed on which of the following?
- A. IDS server
- B. Domain boundary
- C. Screened subnet
- D. Web server
Answer: B
Explanation:
Explanation/Reference:
Explanation:
A border router should be placed on a (security) domain boundary. Placing it on a web server or screened subnet, which is a demilitarized zone (DMZ) would not provide any protection. Border routers are positioned on the boundary of the network, but do not reside on a server.
NEW QUESTION 507
Using which of the following metrics will BEST help to determine the resiliency of IT infrastructure security controls?
- A. Frequency of updates to system software
- B. Number of successful disaster recovery tests
- C. Number of incidents resulting in disruptions
- D. Percentage of outstanding high-risk audit issues
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 508
Which of the following is the MOST important factor in an organization's selection of a key risk indicator (KRI)?
- A. Return on investment
- B. Organizational culture
- C. Compliance requirements
- D. Criticality of information
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 509
Which of the following areas is MOST susceptible to the introduction of security weaknesses?
- A. Database management
- B. Tape backup management
- C. Configuration management
- D. Incident response management
Answer: C
Explanation:
Explanation
Configuration management provides the greatest likelihood of security weaknesses through misconfiguration and failure to update operating system (OS) code correctly and on a timely basis.
NEW QUESTION 510
Which of the following is the MOST important consideration in a bring your own device (BYOD) program to protect company data in the event of a loss?
- A. The ability to remotely locate devices
- B. The ability to centrally manage devices
- C. The ability to classify types of devices
- D. The ability to restrict unapproved applications
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
NEW QUESTION 511
Attacks using multiple methods to spread should be classified:
- A. using multiple classifications for each impact
- B. at the highest potential level of business impact
- C. each time the exposure is experienced
- D. depending on the method used to spread
Answer: B
NEW QUESTION 512
An information security manager suspects that the organization has suffered a ransomware attack. What should be done FIRST
- A. Alert employees to the attack.
- B. Notify senior management
- C. Confirm the infection.
- D. Isolate the affected systems.
Answer: D
NEW QUESTION 513
An organization s HR department would like to outsource its employee management system to a cloud-hosted solution due to features and cost savings offered. Management has identified this solution as a business need and wants to move forward. What should be the PRIMARY role of information security in this effort?
- A. Determine how to securely implement the solution.
- B. Ensure the service provider has the appropriate certifications.
- C. Explain security issues associated with the solution to management.
- D. Ensure a security audit is performed of the service provider.
Answer: C
NEW QUESTION 514
The GREATEST benefit resulting from well-documented information security procedures is that they:
- A. facilitate security training of new staff.
- B. provide a basis for auditing security practices.
- C. ensure that critical processes can be followed by temporary staff.
- D. ensure that security policies are consistently applied.
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 515
An organization's information security manager has learned that similar organizations have become increasingly susceptible to spear phishing attacks. What is the BEST way to address this concern?
- A. Update data loss prevention (DLP) rules for email.
- B. Conduct a business impact analysis (BIA) of the threat.
- C. Include tips to identify threats in awareness training.
- D. Create a new security policy that staff must read and sign.
Answer: C
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 516
Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA)?
- A. Identifying critical business processes
- B. Identifying key business risks
- C. Identifying the threat environment
- D. Identifying risk mitigation options
Answer: B
Explanation:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
NEW QUESTION 517
Which of the following would be MOST critical to the successful implementation of a biometric authentication system?
- A. User acceptance
- B. Technical skills of staff
- C. Password requirements
- D. Budget allocation
Answer: A
Explanation:
Explanation
End users may react differently to the implementation, and may have specific preferences. The information security manager should be aware that what is viewed as reasonable in one culture may not be acceptable in another culture. Budget allocation will have a lesser impact since what is rejected as a result of culture cannot be successfully implemented regardless of budgetary considerations. Technical skills of staff will have a lesser impact since new staff can be recruited or existing staff can be trained. Although important, password requirements would be less likely to guarantee the success of the implementation.
NEW QUESTION 518
A risk assessment study carried out by an organization noted that there is no segmentation of the local area network (LAN). Network segmentation would reduce the potential impact of which of the following?
- A. Virus infections
- B. Traffic sniffing
- C. IP address spoofing
- D. Denial of service (DoS) attacks
Answer: B
Explanation:
Network segmentation reduces the impact of traffic sniffing by limiting the amount of traffic that may be visible on any one network segment. Network segmentation would not mitigate the risk posed by denial of service (DoS) attacks, virus infections or IP address spoofing since each of these would be able to traverse network segments.
NEW QUESTION 519
Which of the following is the BEST method for determining whether new risks exist in legacy systems?
- A. Regularly scheduled security audits
- B. Frequent updates to the risk register
- C. Regularly scheduled risk assessments
- D. Automated vulnerability scans
Answer: D
NEW QUESTION 520
Which item would be the BEST to include in the information security awareness training program for new general staff employees?
- A. Review of roles that have privileged access
- B. Discussion of vulnerability assessment results
- C. Discussion of how to construct strong passwords
- D. Review of various security models
Answer: C
NEW QUESTION 521
The PRIMARY objective of a security steering group is to:
- A. ensure information security aligns with business goals.
- B. raise information security awareness across the organization.
- C. ensure information security covers all business functions.
- D. implement all decisions on security management across the organization.
Answer: A
Explanation:
The security steering group comprises senior management of key business functions and has the primary objective to align the security strategy with the business direction. Option A is incorrect because all business areas may not be required to be covered by information security; but, if they do, the main purpose of the steering committee would be alignment more so than coverage. While raising awareness is important, this goal would not be carried out by the committee itself. The steering committee may delegate part of the decision making to the information security manager; however, if it retains this authority, it is not the primary' goal.
NEW QUESTION 522
Which of the following is PRIMARILY influenced by a business impact analysis (BIA)?
- A. Risk mitigation strategy
- B. Security strategy
- C. IT strategy
- D. Recovery strategy
Answer: A
NEW QUESTION 523
A company recently developed a breakthrough technology. Since this technology could give this company a significant competitive edge, which of the following would FIRST govern how this information is to be protected?
- A. Data classification policy
- B. Encryption standards
- C. Acceptable use policy
- D. Access control policy
Answer: A
Explanation:
Section: INFORMATION RISK MANAGEMENT
Explanation:
Data classification policies define the level of protection to be provided for each category of data. Without this mandated ranking of degree of protection, it is difficult to determine what access controls or levels of encryption should be in place. An acceptable use policy is oriented more toward the end user and, therefore, would not specifically address what controls should be in place to adequately protect information.
NEW QUESTION 524
Which of the following is the BEST evidence that an organization's information security governance framework is effective?
- A. The risk register is reviewed annually.
- B. The framework can adapt to organizational changes.
- C. Threats to the organization have diminished.
- D. The framework focuses primarily on technical controls.
Answer: B
NEW QUESTION 525
To ensure adequate disaster-preparedness among IT infrastructure personnel, it is MOST important to:
- A. assign personnel-specific duties in the recovery plan.
- B. have the most experienced personnel participate in recovery tests.
- C. include end-user personnel in each recovery test.
- D. periodically rotate recovery-test participants.
Answer: D
Explanation:
Section: INFORMATION SECURITY PROGRAM DEVELOPMENT
Explanation/Reference:
NEW QUESTION 526
How would an information security manager balance the potentially conflicting requirements of an international organization's security standards and local regulation?
- A. Negotiate a local version of the organization standards
- B. Make the organization aware of those standards where local regulations causes conflicts
- C. Follow local regulations only
- D. Give organization standards preference over local regulations
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Adherence to local regulations must always be the priority. Not following local regulations can prove detrimental to the group organization. Following local regulations only is incorrect since there needs to be some recognition of organization requirements. Making an organization aware of standards is a sensible step, but is not a total solution. Negotiating a local version of the organization standards is the most effective compromise in this situation.
NEW QUESTION 527
......
ISACA CISM: What career benefits can you get?
Holding the CISM certification will support your career growth. If you are an IT Security Architect, an Information Security Analyst, or a Chief Information Security Officer, this certificate will help you significantly get a promotion or find a new job. It demonstrates your knowledge in the information security sphere and makes finding a new job easier.
In addition, you will surely earn more. The average salary for those professionals who have the CISM certification ranges from $52,400 to $243,600 per year. Therefore, if you want to get a pay raise, this certificate is the right choice for you.
CISM Dumps Real Exam Questions Test Engine Dumps Training: https://testking.practicedump.com/CISM-exam-questions.html