{"id":22223,"date":"2026-09-25T11:42:53","date_gmt":"2026-09-25T11:42:53","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22223"},"modified":"2026-09-25T11:42:53","modified_gmt":"2026-09-25T11:42:53","slug":"isaca-cism-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cism-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Isaca CISM Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cism-exam-dumps\"><b>Isaca CISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 361<\/b><\/h3>\n<p><b>What should be the first consideration when developing a security strategy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business objectives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor products<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office expansion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Staff preferences<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business objectives should be a primary consideration when developing an information security strategy because security exists to support and protect organizational goals. Security leaders should understand the organization\u2019s mission, critical processes, risk tolerance, regulatory obligations, and information requirements before defining strategic priorities. This ensures that security investments address meaningful business risks rather than focusing only on technology or isolated technical weaknesses. CISM emphasizes strategic alignment, requiring security leaders to connect security objectives with enterprise objectives. A strategy built around business needs is more likely to receive appropriate management support and deliver relevant risk reduction.<\/span><\/p>\n<h3><b>Question 362<\/b><\/h3>\n<p><b>Which activity helps management decide between competing security investments?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office inspection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk-based prioritization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee polling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor advertising<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk-based prioritization helps management compare competing security investments by considering potential business impact, likelihood, regulatory requirements, risk tolerance, and expected benefits. Organizations rarely have unlimited security resources, so every initiative cannot receive equal attention. A risk-based approach provides a consistent method for determining which investments address the most significant exposures or support important strategic objectives. CISM emphasizes that security decisions should be based on business risk rather than technology popularity alone. Management can use prioritized risk information to allocate funding, personnel, and time toward initiatives that provide meaningful protection and align with organizational priorities.<\/span><\/p>\n<h3><b>Question 363<\/b><\/h3>\n<p><b>What should an information security charter establish?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product pricing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office schedules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security authority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Marketing targets<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An information security charter should establish the authority, responsibilities, scope, and general purpose of the security function. It provides formal management support and clarifies how security activities relate to organizational governance and business objectives. A well-defined charter can identify reporting relationships, decision-making authority, responsibilities, and expectations for security management. This helps prevent ambiguity and strengthens accountability. CISM emphasizes governance because security programs require appropriate organizational authority to operate effectively. The charter should be approved at the appropriate management level and periodically reviewed to ensure that it continues to reflect organizational structure, strategy, and security requirements.<\/span><\/p>\n<h3><b>Question 364<\/b><\/h3>\n<p><b>Which action best supports security accountability?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared passwords<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Undefined ownership<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Informal approvals<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Documented responsibilities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Documented responsibilities support security accountability by clearly identifying who is responsible for decisions, controls, processes, and security activities. Accountability becomes difficult when responsibilities are informal or overlapping without clear ownership. Documentation should be consistent with organizational roles and authority and should identify appropriate escalation paths. It is also important to ensure that individuals have sufficient authority and resources to perform their assigned responsibilities. CISM emphasizes clear governance and accountability as foundations of effective security management. Periodic review is necessary because reorganizations, new technologies, acquisitions, and changes in business processes can require responsibilities to be updated.<\/span><\/p>\n<h3><b>Question 365<\/b><\/h3>\n<p><b>What should determine information security governance priorities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Staff preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor location<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business risk should determine information security governance priorities because governance activities must address the organization\u2019s most significant exposures and support its objectives. Governance establishes direction, accountability, oversight, and decision-making structures for information security. Priorities should reflect risk tolerance, critical business processes, regulatory requirements, strategic initiatives, and changes in the threat environment. CISM emphasizes that governance should be integrated with enterprise governance rather than operating as an isolated technical function. Management should therefore ensure that governance decisions provide appropriate oversight of security performance, resource allocation, risk treatment, and alignment with organizational objectives.<\/span><\/p>\n<h3><b>Question 366<\/b><\/h3>\n<p><b>What should happen when a security risk exceeds organizational tolerance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hide the risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Escalate the risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the record<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the exposure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A security risk that exceeds organizational risk tolerance should be escalated to the appropriate risk owner or management authority. Management can then determine whether additional controls, risk transfer, process changes, avoidance, or formal risk acceptance are appropriate. Security personnel should provide sufficient information about the likelihood, potential impact, existing controls, and available treatment options. CISM emphasizes that risk acceptance must occur at the appropriate level of authority and should not happen informally. Escalation ensures that significant exposures receive management attention and that decisions remain consistent with established governance, risk appetite, and accountability requirements.<\/span><\/p>\n<h3><b>Question 367<\/b><\/h3>\n<p><b>Which factor should influence security control implementation timing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office availability<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk priority<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor popularity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk priority should influence the timing of security control implementation because resources should generally be directed first toward exposures that present significant business consequences. Organizations should consider risk severity, business criticality, regulatory requirements, dependencies, implementation complexity, and available resources when establishing timelines. A lower-risk control may appropriately be scheduled later if more significant risks require immediate treatment. CISM promotes risk-based prioritization rather than treating every security requirement identically. Implementation plans should also include responsible owners and measurable milestones so management can track progress and determine whether delays create additional exposure requiring escalation or interim controls.<\/span><\/p>\n<h3><b>Question 368<\/b><\/h3>\n<p><b>What should be considered before outsourcing a security function?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office furniture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee hobbies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product packaging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business risk should be considered before outsourcing a security function because external providers may introduce dependencies, access sensitive information, affect critical operations, or create compliance obligations. Management should evaluate the provider\u2019s capabilities, security controls, financial stability, incident response arrangements, service commitments, regulatory responsibilities, and ability to meet organizational requirements. Outsourcing does not transfer ultimate accountability for managing the organization\u2019s security risk. CISM emphasizes third-party risk management throughout the relationship. The organization should therefore establish appropriate contractual requirements, assurance mechanisms, monitoring, and exit arrangements before relying on an external provider for important security services.<\/span><\/p>\n<h3><b>Question 369<\/b><\/h3>\n<p><b>What is an important purpose of security architecture?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Support secure business processes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce employees<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Improve advertising<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security architecture provides a structured approach for integrating security principles and controls into technology and business environments. Its purpose includes supporting secure business processes while addressing identified risks, information flows, system dependencies, and regulatory requirements. Architecture should translate security strategy and business requirements into practical design decisions. It may define principles for identity, network protection, data security, application controls, monitoring, and resilience. CISM emphasizes alignment between security architecture and organizational objectives. Effective architecture should not unnecessarily restrict legitimate business activities; instead, it should provide appropriate protection while enabling the organization to operate efficiently within its accepted level of risk.<\/span><\/p>\n<h3><b>Question 370<\/b><\/h3>\n<p><b>Which activity helps ensure security controls remain effective?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Periodic assessment<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignoring findings<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing metrics<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoiding testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Periodic assessment helps determine whether security controls continue to operate effectively and remain appropriate for current risks and business requirements. Controls may become less effective when technology changes, business processes evolve, threats develop, or configurations are modified. Assessments can include testing, reviews, audits, monitoring, or other assurance activities depending on the control and risk. CISM emphasizes continuous improvement and control effectiveness rather than assuming that implemented controls will remain effective indefinitely. Assessment results should be documented, communicated to appropriate stakeholders, and used to determine whether remediation, redesign, additional monitoring, or other corrective actions are necessary.<\/span><\/p>\n<h3><b>Question 371<\/b><\/h3>\n<p><b>What should guide security awareness content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee hobbies<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Current risks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor advertising<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Current risks should guide security awareness content so training addresses threats and behaviors that are relevant to the organization. Awareness topics may include phishing, credential protection, data handling, social engineering, remote work, reporting procedures, or other risks identified through assessments and incidents. Different roles may require different content because responsibilities and exposure vary across the organization. CISM emphasizes risk-based awareness programs rather than generic training that remains unchanged for long periods. Organizations should also measure behavioral outcomes to determine whether awareness activities are producing meaningful improvements and should update content when threat conditions, business processes, or policies change.<\/span><\/p>\n<h3><b>Question 372<\/b><\/h3>\n<p><b>What should management consider when evaluating security program performance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office size<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Staff preferences<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business outcomes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor popularity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business outcomes should be considered when evaluating security program performance because security activities should contribute to organizational objectives and risk management. Management should examine whether security initiatives are reducing meaningful risks, supporting critical processes, meeting compliance requirements, and delivering expected benefits. Activity counts alone may not demonstrate program effectiveness. For example, the number of completed assessments does not necessarily show whether important vulnerabilities or risks have been reduced. CISM emphasizes outcome-based measurement and business-focused reporting. Security leaders should therefore connect performance indicators with strategic objectives, risk trends, control effectiveness, and management decisions.<\/span><\/p>\n<h3><b>Question 373<\/b><\/h3>\n<p><b>What should happen to a risk after treatment is completed?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remove it permanently<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore it<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reassess residual risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transfer ownership automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After risk treatment is completed, the organization should reassess the residual risk to determine whether the remaining exposure is within acceptable limits. Treatment does not necessarily eliminate all risk because controls may reduce likelihood or impact without completely removing the underlying threat. Reassessment should consider whether controls were implemented as intended and whether they are effective. If residual risk remains above tolerance, additional treatment or management acceptance may be required. CISM emphasizes continuous risk management, meaning risks should be monitored and reassessed as circumstances change rather than being considered permanently resolved after one treatment activity.<\/span><\/p>\n<h3><b>Question 374<\/b><\/h3>\n<p><b>Which element strengthens a security policy exception process?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Informal approval<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">No expiration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Documented justification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Documented justification strengthens a security policy exception process by explaining why the standard requirement cannot be followed and what business need requires the exception. The request should normally identify affected systems, associated risks, proposed compensating controls, responsible owner, approval authority, and an appropriate expiration or review date. Formal documentation creates accountability and allows management to evaluate whether the exception remains justified. CISM emphasizes controlled exception management because uncontrolled exceptions can gradually weaken security standards. Exceptions should therefore be risk-assessed, formally approved, monitored, and periodically reviewed to determine whether the organization can eventually return to standard requirements.<\/span><\/p>\n<h3><b>Question 375<\/b><\/h3>\n<p><b>What should determine the level of security oversight for a critical supplier?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk exposure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office distance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Contract length<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Supplier popularity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk exposure should determine the level of security oversight applied to a critical supplier. Suppliers that support essential business processes, access sensitive information, or create significant operational dependencies may require stronger assurance, more frequent assessments, detailed contractual requirements, and closer monitoring. Oversight should be proportional to the consequences associated with supplier failure or compromise. CISM emphasizes risk-based third-party management throughout the supplier lifecycle. Organizations should also reassess supplier risk when services, technologies, data access, ownership, or business dependencies change. Effective oversight provides management with assurance that important third-party risks are being identified and appropriately addressed.<\/span><\/p>\n<h3><b>Question 376<\/b><\/h3>\n<p><b>Which action supports continuous security improvement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Freeze procedures<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore incidents<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Review lessons learned<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Reviewing lessons learned supports continuous security improvement by allowing organizations to identify weaknesses and make changes based on actual experience. Lessons can come from incidents, exercises, assessments, audits, control failures, and changes in the threat environment. The review should identify actionable improvements, assign responsibility, and establish appropriate timelines for completion. Simply documenting lessons without implementing changes provides limited value. CISM emphasizes continual improvement as an important part of security management. Organizations should use lessons learned to strengthen policies, controls, training, architecture, communication procedures, and resource planning so recurring weaknesses are progressively reduced.<\/span><\/p>\n<h3><b>Question 377<\/b><\/h3>\n<p><b>What should be considered when setting security objectives?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business strategy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office capacity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Staff age<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor location<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business strategy should be considered when setting security objectives because security objectives need to support the organization\u2019s direction and protect the activities that are important to achieving business goals. Objectives should be specific enough to guide security initiatives and measurable enough to evaluate progress. They should also reflect risk tolerance, regulatory obligations, critical assets, and available resources. CISM emphasizes strategic alignment, meaning security objectives should not be developed independently of enterprise priorities. Regular review is important because changes in business strategy, technology, regulations, or threats may require security objectives to be adjusted.<\/span><\/p>\n<h3><b>Question 378<\/b><\/h3>\n<p><b>Which approach best supports security resource allocation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Equal funding<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Historical spending<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Risk-based allocation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employee requests<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk-based allocation supports effective security resource decisions by directing funding, personnel, and technology toward areas where security weaknesses could have significant business consequences. Resources should be considered against risk severity, business criticality, regulatory obligations, strategic objectives, and expected risk reduction. Equal funding across all departments may appear consistent but may not address the organization\u2019s most important exposures. CISM emphasizes that security resources should be aligned with organizational risk and business requirements. Management should also reassess allocations periodically because risks, priorities, and business conditions change over time.<\/span><\/p>\n<h3><b>Question 379<\/b><\/h3>\n<p><b>What should be reviewed when security responsibilities become unclear after reorganization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Office design<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Governance structure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Product pricing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Vendor advertising<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The governance structure should be reviewed when security responsibilities become unclear after an organizational reorganization. Changes in reporting relationships, departments, leadership, or business processes can create gaps or overlaps in accountability. Management should clarify ownership, authority, escalation paths, decision rights, and responsibilities for important security activities. Updated documentation and communication can help employees understand the revised structure. CISM emphasizes clear accountability because effective governance depends on knowing who has responsibility and authority for security decisions. Reorganizations should therefore trigger appropriate governance reviews to ensure that security responsibilities remain clearly assigned and aligned with organizational objectives.<\/span><\/p>\n<h3><b>Question 380<\/b><\/h3>\n<p><b>What should be the objective of security program reporting?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase technical detail<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Demonstrate business value<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reduce communication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Avoid management review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security program reporting should demonstrate business value by showing management how security activities affect risk, organizational objectives, compliance, resilience, and resource requirements. Reports should be tailored to the audience, with executives generally needing concise information about significant risks, trends, performance, and decisions rather than extensive technical details. Effective reporting should use reliable metrics and provide enough context for management to understand the significance of the information. CISM emphasizes business-focused communication because security leaders must help management make informed decisions. Reporting should therefore connect security performance to organizational outcomes and highlight areas where management action or resources may be required.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISM Exam Dumps and Practice Test Dumps. &nbsp; Question 361 What should be the first consideration when developing a security strategy? Business objectives Vendor products Office expansion Staff preferences Correct Answer: 1 Explanation Business objectives should be a primary consideration when developing an information security strategy because security exists to support and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22223"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22223"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22223\/revisions"}],"predecessor-version":[{"id":22224,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22223\/revisions\/22224"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}