{"id":22221,"date":"2026-09-25T11:42:39","date_gmt":"2026-09-25T11:42:39","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22221"},"modified":"2026-09-25T11:42:39","modified_gmt":"2026-09-25T11:42:39","slug":"isaca-cism-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cism-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"Isaca CISM Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cism-exam-dumps\"><b>Isaca CISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 341<\/b><\/h3>\n<p><b>What should determine security program priorities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office size<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee requests<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business risk should determine security program priorities because security resources should be directed toward risks that could significantly affect organizational objectives. Prioritization should consider business impact, likelihood, regulatory requirements, critical information assets, and organizational risk tolerance. Security teams should avoid selecting initiatives simply because they are technologically attractive or requested by a particular department. A risk-based approach allows management to make informed decisions about competing security investments. CISM emphasizes alignment between security programs and business objectives, ensuring that security activities address meaningful organizational exposures while supporting important operational and strategic requirements.<\/span><\/p>\n<h3><b>Question 342<\/b><\/h3>\n<p><b>Which activity helps identify gaps between current and required security capabilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gap analysis<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sales review<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office survey<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A gap analysis compares the organization\u2019s current security capabilities with the capabilities required to meet business objectives, regulatory obligations, and risk management expectations. It can identify weaknesses in personnel, processes, technology, governance, controls, or security services. The results help management determine which gaps require immediate attention and which can be addressed through longer-term planning. CISM emphasizes capability assessment as part of effective security program management. A well-conducted gap analysis should be based on defined requirements and organizational priorities rather than assumptions. It can also support budgeting, resource planning, and development of a security improvement roadmap.<\/span><\/p>\n<h3><b>Question 343<\/b><\/h3>\n<p><b>What is the main purpose of a security program roadmap?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Track office moves<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schedule vacations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prioritize improvements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Manage sales<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security program roadmap provides a structured view of planned security initiatives, priorities, dependencies, resources, and expected outcomes over time. It helps management understand how the security program will progress from its current state toward desired capabilities. Initiatives should be prioritized according to business risk, regulatory requirements, organizational objectives, and available resources. A roadmap also helps coordinate activities that depend on one another and prevents disconnected security investments. CISM emphasizes strategic planning and alignment, making the roadmap a useful management tool for communicating priorities and ensuring that security improvements are implemented in a logical and sustainable manner.<\/span><\/p>\n<h3><b>Question 344<\/b><\/h3>\n<p><b>When resources are limited, which initiative should receive greater consideration?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Low-impact project<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">High-risk exposure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Optional upgrade<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cosmetic change<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A high-risk exposure should generally receive greater consideration when resources are limited because it may create significant consequences for critical business objectives. Prioritization should consider the likelihood and impact of the risk, regulatory requirements, business criticality, existing controls, and available treatment options. This does not mean every high-risk issue must immediately receive the same treatment; management should compare competing risks and expected benefits. CISM emphasizes risk-based resource allocation, allowing organizations to direct limited security resources toward areas where they can provide meaningful risk reduction and support organizational objectives.<\/span><\/p>\n<h3><b>Question 345<\/b><\/h3>\n<p><b>What should a security budget primarily reflect?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business priorities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee preferences<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office location<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor popularity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security budget should reflect business priorities, organizational risks, regulatory obligations, and the resources required to achieve security objectives. Budget decisions should be connected to the organization\u2019s security strategy and should explain how proposed investments support important business outcomes. A budget based primarily on historical spending or technology popularity may fail to address current risks. CISM emphasizes demonstrating business value when requesting security resources. Security leaders should therefore communicate expected benefits, risks addressed, resource requirements, and consequences of insufficient funding. This allows management to compare security investments with other organizational priorities and make informed resource decisions.<\/span><\/p>\n<h3><b>Question 346<\/b><\/h3>\n<p><b>What should be reviewed before approving a major security initiative?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office furniture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business case<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee birthdays<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product packaging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A business case should be reviewed before approving a major security initiative because management needs to understand the justification, expected benefits, costs, risks, dependencies, and resource requirements. The business case should explain how the initiative supports organizational objectives and what risks or regulatory requirements it addresses. It should also consider alternatives and the consequences of not proceeding. CISM emphasizes that security investments should be justified in business terms rather than solely through technical arguments. A clear business case enables management to compare initiatives consistently and determine whether the expected value and risk reduction justify the required investment.<\/span><\/p>\n<h3><b>Question 347<\/b><\/h3>\n<p><b>Which approach helps maintain accountability for security responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared ambiguity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Informal assignments<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Undefined ownership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clear responsibility<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Clear responsibility helps maintain accountability because individuals and functions need to understand who is responsible for specific security decisions and activities. Responsibilities should be documented and aligned with organizational authority, job functions, and business requirements. Ambiguous ownership can lead to missed tasks, delayed decisions, duplicated effort, or unmanaged risks. CISM emphasizes governance structures that establish clear accountability across security and business functions. Responsibility should also include appropriate authority and resources so assigned individuals can fulfill their roles effectively. Periodic reviews are useful because organizational changes may require responsibilities to be reassigned or updated.<\/span><\/p>\n<h3><b>Question 348<\/b><\/h3>\n<p><b>Why is segregation of duties important in security management?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce accountability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Prevent conflicts<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase privileges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove oversight<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Segregation of duties reduces the risk that one individual can perform conflicting activities without adequate oversight. For example, the person requesting a privileged access change should not necessarily be the same person who independently approves and implements it. Separating responsibilities creates checks and balances that can reduce fraud, misuse, unauthorized changes, and errors. The exact separation should reflect the organization\u2019s risk and operational structure. CISM emphasizes governance and accountability, meaning security responsibilities should be designed so that critical actions receive appropriate review. Where complete separation is impractical, compensating controls may provide additional oversight.<\/span><\/p>\n<h3><b>Question 349<\/b><\/h3>\n<p><b>What should happen when an employee changes roles?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keep all access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Add privileges<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disable monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an employee changes roles, their access should be reviewed to ensure permissions remain appropriate for the new responsibilities. Access that was necessary for the previous role may no longer be required and could create unnecessary risk if retained. The review should consider least privilege, segregation of duties, sensitive information, and privileged access. Appropriate permissions should be removed or modified according to organizational procedures. CISM emphasizes lifecycle management of access because security risks can arise when permissions do not reflect current responsibilities. Role changes should therefore trigger timely access reviews rather than relying on users to request changes themselves.<\/span><\/p>\n<h3><b>Question 350<\/b><\/h3>\n<p><b>Which principle limits access to only what a user needs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Defense in depth<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk transfer<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Separation of networks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege limits users, applications, and processes to the minimum access necessary to perform authorized responsibilities. This reduces the potential impact of compromised accounts, insider misuse, accidental changes, and unauthorized access. Privileges should be based on job requirements and reviewed periodically because responsibilities change over time. Highly privileged access should receive additional controls such as stronger authentication, monitoring, approval, and logging. CISM emphasizes risk-based access management, meaning permissions should support legitimate business needs without creating unnecessary exposure. Least privilege is therefore an important principle for protecting sensitive information and limiting the potential consequences of security incidents.<\/span><\/p>\n<h3><b>Question 351<\/b><\/h3>\n<p><b>What should be required for sensitive privileged access?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Informal approval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business justification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Permanent access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared credentials<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sensitive privileged access should have a documented business justification and appropriate authorization because privileged accounts can make significant changes to systems, data, and security controls. Access should be limited to legitimate responsibilities and granted according to established policies. Organizations should also consider stronger authentication, monitoring, logging, periodic review, and time-limited access where appropriate. Shared credentials reduce accountability and should generally be avoided when individual identities can be used. CISM emphasizes controlling high-risk access through governance and accountability. Proper authorization ensures that privileged permissions are necessary, traceable, and consistent with organizational risk requirements.<\/span><\/p>\n<h3><b>Question 352<\/b><\/h3>\n<p><b>What should security leaders consider when adopting a new technology?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product color<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office furniture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee hobbies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business risk should be considered when adopting new technology because new technologies can introduce changes to architecture, data flows, access requirements, third-party dependencies, compliance obligations, and threat exposure. Security leaders should evaluate how the technology supports business objectives and what risks may result from its implementation. The assessment should consider security requirements, control effectiveness, integration issues, data protection, operational impact, and regulatory considerations. CISM emphasizes that security should enable business objectives while managing risk. Technology adoption should therefore involve appropriate security and risk assessment rather than being based solely on features, cost, or market popularity.<\/span><\/p>\n<h3><b>Question 353<\/b><\/h3>\n<p><b>Which factor should influence security architecture decisions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office decoration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor advertising<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee preference<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business requirements should influence security architecture decisions because architecture must support organizational processes while providing appropriate protection for information and technology assets. Security architecture decisions should consider business objectives, risk tolerance, regulatory obligations, information flows, system dependencies, and required security controls. A technically sophisticated architecture may not provide appropriate value if it prevents essential business activities or fails to address significant risks. CISM emphasizes alignment between security strategy and enterprise requirements. Security architecture should therefore translate strategic objectives and risk decisions into practical design principles and controls that can be implemented and maintained throughout the technology lifecycle.<\/span><\/p>\n<h3><b>Question 354<\/b><\/h3>\n<p><b>What is the main benefit of defense in depth?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multiple protections<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fewer controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single protection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduced monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses multiple layers of security controls so that failure or bypass of one control does not automatically result in complete compromise. Layers may include preventive, detective, corrective, administrative, physical, and technical controls. The approach can reduce the likelihood and impact of successful attacks by creating multiple opportunities to detect or stop malicious activity. Controls should still be selected according to risk and business requirements rather than added without justification. CISM emphasizes layered protection as part of effective security architecture, particularly for critical assets and processes where reliance on a single control would create unacceptable exposure.<\/span><\/p>\n<h3><b>Question 355<\/b><\/h3>\n<p><b>What should happen when controls overlap unnecessarily?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the overlap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Add more controls<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Assess rationalization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unnecessary control overlap should be assessed through control rationalization to determine whether duplicated controls provide meaningful additional protection or create avoidable complexity and cost. Some overlap may be intentional as part of defense in depth, while other duplication may result from disconnected initiatives or legacy requirements. Organizations should evaluate control effectiveness, risk reduction, operational burden, and compliance requirements before deciding whether controls should be combined, retained, modified, or removed. CISM emphasizes efficient use of security resources, so rationalization can help simplify security architecture while preserving appropriate protection and meeting organizational and regulatory requirements.<\/span><\/p>\n<h3><b>Question 356<\/b><\/h3>\n<p><b>What should happen after a major business acquisition?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore existing strategy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reassess security strategy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove all policies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stop monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A major business acquisition should trigger reassessment of the security strategy because the organization may inherit new systems, information assets, users, suppliers, technologies, regulations, and security risks. Existing security policies, architecture, controls, and resources may not adequately address the combined environment. Management should evaluate differences in risk tolerance, governance, regulatory requirements, security capabilities, and business priorities. CISM emphasizes strategic alignment and continuous reassessment when significant organizational changes occur. The objective is not simply to integrate technologies but to establish a security approach that supports the expanded organization while maintaining appropriate governance, risk management, and protection.<\/span><\/p>\n<h3><b>Question 357<\/b><\/h3>\n<p><b>What should guide security program maturity improvement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk and objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office size<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Staff preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor popularity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk and organizational objectives should guide security program maturity improvement because maturity should reflect what the organization needs to achieve and the level of risk it must manage. Not every organization requires the same security capabilities or maturity level. Management should identify current capabilities, desired outcomes, significant gaps, and the resources needed to close those gaps. Improvements should be prioritized according to business impact, risk tolerance, regulatory obligations, and strategic requirements. CISM emphasizes a business-aligned approach to security management, ensuring that maturity investments provide practical value instead of pursuing maturity for its own sake.<\/span><\/p>\n<h3><b>Question 358<\/b><\/h3>\n<p><b>What is an important characteristic of an effective security policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Technical complexity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Frequent exceptions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clear requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Informal wording<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Clear requirements are an important characteristic of an effective security policy because employees and management need to understand expected security behaviors, responsibilities, and boundaries. A policy should provide authoritative direction without becoming so technically detailed that it becomes difficult to maintain. Supporting standards, procedures, and guidelines can provide implementation details. Policies should be approved by appropriate management authority and reviewed periodically to ensure continued alignment with business objectives, laws, regulations, and risks. CISM emphasizes management direction and accountability, so security policies should be understandable, enforceable, and supported by appropriate governance mechanisms.<\/span><\/p>\n<h3><b>Question 359<\/b><\/h3>\n<p><b>What should determine how often a security policy is reviewed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk and change<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office schedule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Staff birthdays<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor preference<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk and organizational change should influence the frequency of security policy reviews. Significant changes in business processes, technology, regulations, threats, organizational structure, or risk tolerance may make existing policy requirements outdated. Policies should also be reviewed according to established governance requirements even when no major change occurs. The review should determine whether responsibilities, requirements, exceptions, and enforcement mechanisms remain appropriate. CISM emphasizes continuous alignment between security governance and organizational needs. Regular policy review helps ensure that management direction remains relevant and that employees are operating under requirements that accurately reflect current risks and business conditions.<\/span><\/p>\n<h3><b>Question 360<\/b><\/h3>\n<p><b>What should a security program do when business objectives change significantly?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Continue unchanged<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce oversight<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reassess alignment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When business objectives change significantly, the security program should reassess its alignment with the organization\u2019s new direction. Changes such as entering new markets, launching digital services, acquiring businesses, or modifying operating models can create new information security requirements and risks. Security leaders should evaluate whether existing strategy, policies, architecture, resources, controls, and metrics remain appropriate. CISM emphasizes that security should support business objectives rather than operate independently from them. Reassessment allows management to identify new priorities, address emerging exposures, and redirect resources where necessary while maintaining an appropriate balance between business enablement, security, compliance, and risk management.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISM Exam Dumps and Practice Test Dumps. &nbsp; Question 341 What should determine security program priorities? Office size Business risk Vendor preference Employee requests Correct Answer: 2 Explanation Business risk should determine security program priorities because security resources should be directed toward risks that could significantly affect organizational objectives. Prioritization should consider [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22221"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22221"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22221\/revisions"}],"predecessor-version":[{"id":22222,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22221\/revisions\/22222"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}