View Full Isaca CISM Exam Dumps and Practice Test Dumps.
Question 121
What is the PRIMARY purpose of an information security charter?
- To document individual employee performance
- To define the authority, responsibilities, and objectives of the security function
- To replace all technical security procedures
- To identify every vulnerability in the organization
Correct Answer: 2
Explanation
An information security charter establishes the mandate, authority, responsibilities, and objectives of the information security function. It helps clarify the security manager’s role, reporting relationships, decision-making authority, and relationship with other business functions. A charter does not replace detailed procedures or serve as a vulnerability inventory. By formally defining the security function’s scope and authority, the organization can reduce ambiguity and establish appropriate accountability. The charter should align with organizational governance and business objectives so that security activities support enterprise priorities rather than operating as an isolated technical function.
Question 122
Which activity BEST demonstrates integration of information security governance with enterprise governance?
- Allowing security decisions to be made independently of business priorities
- Reporting only technical vulnerabilities to the security team
- Including information security risk in enterprise decision-making processes
- Restricting security oversight to the IT department
Correct Answer: 3
Explanation
Information security governance is integrated with enterprise governance when security risks, objectives, and responsibilities are incorporated into broader organizational decision-making. This means management considers information security when approving strategies, investments, acquisitions, new products, suppliers, and major business changes. Restricting security decisions to IT can separate security from the business context that determines risk priorities. Similarly, reporting only technical vulnerabilities may not provide executives with sufficient information for enterprise decisions. Effective integration ensures that security considerations are addressed alongside financial, operational, legal, and strategic factors through established governance structures.
Question 123
Which document typically provides mandatory high-level direction for information security across an organization?
- Security policy
- Technical troubleshooting guide
- Individual work instruction
- Informal email
Correct Answer: 1
Explanation
A security policy provides high-level mandatory direction and establishes management’s expectations for protecting organizational information and systems. Policies typically define principles, responsibilities, required behaviors, and broad security requirements without describing every operational step. Standards can provide more specific mandatory requirements, while procedures generally explain how activities are performed. Informal communications and troubleshooting guides may provide useful information but do not normally establish enterprise-wide governance requirements. A well-designed policy should be approved by appropriate management, communicated to relevant personnel, reviewed periodically, and aligned with business objectives, legal obligations, and the organization’s risk environment.
Question 124
An organization is developing a new security standard to support an existing policy. What should the standard primarily provide?
- Optional recommendations that employees may ignore
- Detailed mandatory requirements that support the policy
- Strategic business objectives for senior executives
- A list of previously reported incidents
Correct Answer: 2
Explanation
A security standard translates broad policy requirements into specific, mandatory requirements that can be consistently applied across the organization. For example, a policy may require strong authentication, while a standard could define minimum password, authentication, or multifactor requirements. Standards are more specific than policies but generally do not provide the step-by-step instructions found in procedures. Keeping these layers distinct improves governance and makes requirements easier to communicate and enforce. Standards should remain aligned with business needs, risk levels, legal obligations, and technological conditions and should be reviewed when relevant requirements change.
Question 125
Which role should generally be accountable for making business decisions about an information asset?
- The help desk technician
- The information asset owner
- The external auditor
- The network administrator
Correct Answer: 2
Explanation
The information asset owner is generally responsible for making business decisions concerning an asset, including its classification, appropriate protection requirements, access needs, and acceptable use. Technical administrators may implement and operate controls, but they do not necessarily have the authority to determine the business value or sensitivity of the information. External auditors independently evaluate controls and compliance rather than owning organizational assets. Clear ownership helps ensure that security requirements reflect business needs and that decisions about protection and risk are made by someone with appropriate authority and knowledge of the asset’s importance.
Question 126
A board asks whether the organization’s information security program is supporting business objectives. Which information would be MOST useful?
- The number of firewall rules created
- The number of security tools installed
- Trends showing security risk, business impact, and progress against objectives
- The number of help desk tickets closed
Correct Answer: 3
Explanation
Senior management and boards generally need information that connects security activities to organizational objectives, risk exposure, and business outcomes. Metrics showing changes in significant risks, control effectiveness, incident impact, regulatory exposure, and progress against strategic objectives are more useful than isolated technical activity counts. The number of firewall rules or security tools may describe activity but does not demonstrate whether business risk is being managed effectively. Effective executive reporting should be concise, relevant, and presented in business terms so that leaders can understand important exposures, trends, decisions required, and the value of security investments.
Question 127
A security steering committee is established to improve coordination between business units and information security. What should be its PRIMARY function?
- Perform every technical security task
- Replace the responsibilities of business owners
- Provide governance, direction, and cross-functional coordination
- Manage individual employee passwords
Correct Answer: 3
Explanation
A security steering committee can provide cross-functional governance by bringing together representatives from business and technology functions to coordinate security priorities, review significant risks, and support alignment with organizational objectives. It should not become a substitute for operational security teams or business owners. Its value comes from providing appropriate direction, resolving cross-functional issues, supporting prioritization, and facilitating management decisions. The committee’s authority and responsibilities should be clearly defined. Strong governance structures help ensure that information security decisions reflect enterprise requirements rather than being driven solely by technical considerations.
Question 128
Which characteristic is MOST important when assigning accountability for information security activities?
- Responsibilities should be clearly defined and aligned with authority
- Responsibilities should remain informal
- Every responsibility should belong to the security department
- Accountability should change whenever an incident occurs
Correct Answer: 1
Explanation
Effective accountability requires clearly defined responsibilities that are matched with sufficient authority and resources to perform the assigned activities. If individuals are held responsible without having the authority to make decisions or obtain necessary resources, accountability becomes ineffective. Information security responsibilities should not automatically be assigned to the security department because business and technology functions also have important obligations. Informal or constantly changing accountability can create gaps and confusion. Clearly documented roles, responsibilities, escalation paths, and decision rights help ensure that security activities are consistently performed and that issues have identifiable owners.
Question 129
A company is entering a new country where different privacy laws apply. What should the security manager do FIRST?
- Identify and assess the applicable legal and regulatory requirements
- Deploy the same controls used in the existing country
- Wait for a regulatory violation before changing processes
- Remove all data from the new market
Correct Answer: 1
Explanation
Entering a new jurisdiction can introduce different privacy, security, data handling, retention, transfer, and reporting requirements. The security manager should first identify and assess the applicable legal and regulatory obligations and determine how they affect the organization’s information security program. Existing controls may be useful but should not automatically be assumed sufficient because legal requirements can differ. Waiting for a violation is reactive and potentially costly. Removing all data may also be impractical or unnecessary. Understanding applicable obligations provides the foundation for identifying gaps, modifying controls, assigning responsibilities, and managing compliance-related risks.
Question 130
What is the PRIMARY benefit of maintaining a formal policy hierarchy?
- It ensures every employee writes individual policies
- It connects broad management direction with specific requirements and procedures
- It eliminates the need for security standards
- It prevents policies from ever being updated
Correct Answer: 2
Explanation
A policy hierarchy provides a structured relationship between high-level management direction and the detailed requirements used in daily operations. Policies establish broad mandatory principles, standards translate those principles into specific requirements, and procedures explain how activities should be performed. Guidelines may provide recommended approaches where flexibility is appropriate. This structure improves consistency, accountability, and communication while allowing different levels of detail to be managed appropriately. It also makes updates easier because a change in policy can be reflected through related standards and procedures without requiring every document to serve the same purpose.
Question 131
A security policy exception is requested because a business process cannot currently meet a mandatory requirement. What should happen FIRST?
- Approve the exception permanently without analysis
- Assess the business justification, associated risk, and available compensating controls
- Disable the affected security control
- Ignore the request until an incident occurs
Correct Answer: 2
Explanation
A policy exception should be evaluated through a defined governance process. The organization should understand why the requirement cannot be met, assess the resulting risk, determine whether compensating controls are available, and obtain approval from the appropriate authority. Permanent approval without analysis can create unmanaged exposure, while disabling controls may increase risk unnecessarily. The exception should also have appropriate documentation, scope, ownership, and review or expiration conditions where applicable. A formal exception process allows the organization to balance legitimate business requirements with security objectives while ensuring that deviations from policy remain visible and accountable.
Question 132
Which factor should MOST influence the frequency of compliance monitoring?
- The color of the organization’s security dashboard
- The risk, regulatory significance, and potential impact of noncompliance
- The number of employees in the security department alone
- The age of the organization’s logo
Correct Answer: 2
Explanation
Compliance monitoring frequency should reflect the significance and risk associated with the requirement. Requirements involving highly sensitive information, critical operations, significant regulatory obligations, or severe consequences may warrant more frequent monitoring. A risk-based approach helps organizations use monitoring resources efficiently instead of applying identical schedules to every requirement. Staffing levels may affect how monitoring is performed, but they should not independently determine the importance of compliance. Monitoring should also consider changes in regulations, business processes, control effectiveness, prior findings, and emerging risks so that significant compliance exposures receive appropriate management attention.
Question 133
Which action BEST demonstrates effective security culture?
- Employees report suspected security issues through established channels
- Employees avoid reporting incidents to prevent negative attention
- Managers handle all security decisions without employee involvement
- Security responsibilities are limited to technical staff
Correct Answer: 1
Explanation
A positive security culture encourages employees to recognize and report security concerns through established channels. Employees are often the first to notice suspicious activity, policy violations, social engineering attempts, or unusual system behavior. A culture that discourages reporting can delay detection and increase potential impact. Security culture also involves leadership behavior, accountability, awareness, training, and integration of security into normal business activities. Technical teams remain important, but effective security requires participation across the organization. Measuring reporting behavior, awareness outcomes, and employee understanding can help determine whether security expectations are becoming part of everyday organizational behavior.
Question 134
A business unit repeatedly fails to comply with a security requirement despite receiving training. What should the CISM examine NEXT?
- Whether the requirement, process, incentives, and underlying causes are appropriate
- Whether training should simply be repeated indefinitely
- Whether the business unit should be removed from the organization
- Whether the requirement should automatically be abandoned
Correct Answer: 1
Explanation
Repeated noncompliance after training suggests that training alone may not address the underlying problem. The CISM should examine whether the requirement is clearly communicated, practical, properly enforced, supported by appropriate processes, and aligned with business activities. Root causes may include unclear responsibilities, inadequate system design, conflicting incentives, excessive process complexity, insufficient management support, or ineffective controls. Repeating training without understanding the cause may not improve behavior. The organization should use evidence from monitoring and incident data to determine appropriate corrective actions while maintaining accountability for required security practices.
Question 135
Which metric would BEST demonstrate whether a security awareness program is changing employee behavior?
- Number of training slides created
- Percentage of employees attending training sessions
- Reduction in repeated risky behaviors measured through appropriate assessments
- Total cost of the training platform
Correct Answer: 3
Explanation
Behavioral outcomes provide stronger evidence of awareness effectiveness than simple activity measures. A reduction in repeated risky behaviors, improved reporting of suspicious activity, or better performance during controlled assessments can demonstrate whether employees are applying security knowledge. Training attendance and the number of materials produced measure program activity but do not necessarily demonstrate behavior change. Cost is useful for financial analysis but does not measure effectiveness. Awareness programs should therefore use appropriate outcome-oriented metrics alongside participation measures. Results can help security leaders identify where additional communication, process changes, or targeted training may be necessary.
Question 136
An organization wants to determine whether its security program has sufficient resources to meet strategic objectives. Which approach is MOST appropriate?
- Compare available capabilities and resources with defined security objectives and risk requirements
- Compare its staffing only with competitors
- Increase the budget by a fixed percentage every year
- Purchase additional tools before assessing requirements
Correct Answer: 1
Explanation
Resource adequacy should be determined by comparing current capabilities with the organization’s security objectives, risk exposure, required controls, business needs, and compliance obligations. This assessment may include staffing, skills, technology, processes, funding, external services, and operational capacity. Comparing staffing only with competitors may be misleading because organizations have different risks and business models. Automatic budget increases do not demonstrate actual need, while purchasing tools before identifying requirements can create unnecessary complexity. A documented capability gap analysis provides management with evidence for resource decisions and helps prioritize investments according to business and security priorities.
Question 137
What is the PRIMARY purpose of security program maturity assessment?
- To assign blame for previous security incidents
- To identify capability gaps and opportunities for improvement
- To eliminate the need for performance metrics
- To determine which security vendor should be purchased
Correct Answer: 2
Explanation
Security program maturity assessment helps an organization understand the current capability and consistency of its security practices and identify areas requiring improvement. It can evaluate governance, risk management, processes, people, technology, measurement, and other program components against an established model or defined organizational expectations. The purpose is not to assign blame or automatically select a vendor. Maturity information can support roadmap development, investment decisions, resource planning, and continuous improvement. Assessments are most useful when their findings are connected to business objectives and risk priorities rather than treated as an isolated compliance exercise.
Question 138
A security program introduces a new control that creates significant delays in a critical business process. What should be evaluated FIRST?
- Whether the control’s security benefit is proportionate to its business impact and risk
- Whether the control should remain permanently regardless of consequences
- Whether users should bypass the control
- Whether the process should be discontinued immediately
Correct Answer: 1
Explanation
Security controls should protect the organization without creating unnecessary or disproportionate business disruption. When a control significantly affects a critical process, the CISM should evaluate its effectiveness, security benefit, residual risk, operational impact, and alignment with business requirements. The goal is not automatically to remove the control or allow users to bypass it. Alternative designs, compensating controls, automation, process changes, or risk-based adjustments may provide appropriate protection with less disruption. Evaluating both security and business consequences supports balanced decision-making and helps ensure that controls contribute to organizational objectives rather than unnecessarily obstructing them.
Question 139
Which activity is MOST useful for ensuring security requirements are addressed before acquiring a critical third-party service?
- Reviewing the provider’s marketing materials only
- Defining security requirements and assessing the provider against them before contract approval
- Waiting until the first incident to evaluate the provider
- Allowing the provider to define all security requirements independently
Correct Answer: 2
Explanation
Security requirements should be defined and assessed before a critical third-party service is acquired or formally committed. Requirements may address data protection, access management, incident notification, business continuity, compliance, audit rights, vulnerability management, subcontractors, and termination responsibilities. Reviewing marketing materials alone does not provide sufficient assurance. Waiting for an incident is reactive, while allowing the provider to define all requirements may fail to address the organization’s specific risks. Early assessment enables the organization to identify unacceptable gaps, negotiate appropriate contractual protections, and make informed decisions about whether the service aligns with business and security requirements.
Question 140
A security program review identifies that several controls are effective individually but create unnecessary duplication. What should the CISM recommend?
- Remove all duplicate controls immediately
- Analyze control objectives, risks, dependencies, and costs before rationalizing the controls
- Add more controls to increase security coverage
- Ignore the duplication because every additional control always improves security
Correct Answer: 2
Explanation
Control duplication should be evaluated before any controls are removed. Multiple controls may appear similar while addressing different risks, providing defense in depth, or serving separate regulatory and business requirements. The CISM should analyze control objectives, effectiveness, dependencies, residual risk, operational costs, and compliance obligations to determine whether rationalization is appropriate. Removing controls solely because they appear redundant could create security gaps. Conversely, unnecessary duplication can increase complexity and cost. A structured control rationalization process helps maintain appropriate protection while improving efficiency, reducing unnecessary overhead, and ensuring that the security program remains aligned with organizational risk objectives.