Sample ISACA CISM CISM Practice Questions
Q: What is the PRIMARY purpose of an information security governance framework?
A: To ensure security strategies are aligned with business objectives — The primary purpose of information security governance is to ensure that security strategies support and align with the organization's business objectives. Technical controls like antivirus, penetration testing, and firewall management are operational activities, not governance functions.
Q: What is the PRIMARY objective of information security risk management?
A: To identify, assess, and treat risks to an acceptable level aligned with business objectives — The primary objective of risk management is to identify, assess, and treat risks to a level acceptable to the organization in alignment with business objectives. Eliminating all risk is neither feasible nor cost-effective.
Q: What is the PRIMARY goal of an information security program?
A: To protect the organization's information assets while supporting business objectives — The primary goal of an information security program is to protect the organization's information assets while supporting and enabling business objectives. It must balance security with business needs rather than pursuing security for its own sake.
Q: What is the PRIMARY objective of an incident response plan?
A: To minimize the impact of security incidents on business operations — The primary objective of an incident response plan is to minimize the adverse impact of security incidents on business operations. While the plan may help with audits and threat mitigation, its fundamental purpose is business protection and rapid recovery.
Q: Which of the following BEST ensures that information security governance is effective?
A: Establishing a security steering committee with senior management representation — A security steering committee with senior management representation ensures governance effectiveness by providing executive oversight, strategic direction, and accountability. Technology deployments and staffing are operational concerns that fall under governance direction.
Q: An information security manager discovers that the security strategy does not support a new business initiative. What should be done FIRST?
A: Assess the business initiative and update the security strategy accordingly — The security strategy must evolve to support legitimate business initiatives. The first step is to assess the initiative's requirements and update the security strategy to align with the new business direction while maintaining appropriate risk management.
Q: Which metric BEST demonstrates the alignment of information security with business strategy?
A: Percentage of security projects that support documented business objectives — The percentage of security projects supporting documented business objectives directly measures strategic alignment. Incident counts, spending totals, and patch counts are operational metrics that do not inherently demonstrate alignment with business strategy.
Q: Who has ULTIMATE accountability for information security governance in an organization?
A: The Board of Directors or senior management — Ultimate accountability for information security governance rests with the board of directors or senior management. While the CISO manages day-to-day security operations and strategy, governance accountability is a board-level responsibility that cannot be delegated.
Q: What is the MOST important consideration when developing an information security policy?
A: That it aligns with organizational goals and regulatory requirements — Security policies must align with organizational goals and regulatory requirements to be effective and enforceable. Policies should be written at a high level without specific technical details, in language accessible to all stakeholders.
Q: An organization is implementing a new information security governance framework. Which of the following should be established FIRST?
A: Information security policies aligned with business objectives — Policies aligned with business objectives form the foundation of a governance framework. All other elements, including awareness training, vulnerability management, and incident response, derive their authority and direction from established policies.