CISM Domain 1 Questions Set-1: INFORMATION SECURITY GOVERNANCE
1. Which processes are typically
included in information security governance?
a) Personnel management,
sourcing, and change management
b) Configuration management,
access management, and business continuity planning
c) Risk management, vulnerability
management, and incident management
d) All of the above
2. What is a key component of information security
governance?
a) Continuous improvement of
security processes
b) Effective organization
structure and role definition
c) Balanced scorecard and metrics
monitoring
d) All of the above
3. Why do organizations that lack
information security face a business problem?
a)
b) Inadequate technology
solutions
c) Insufficient personnel
management
d) Lack of understanding and commitment by senior executives
4. What is the main challenge faced by organizations in
managing information security at the boardroom level?
a) Lack of awareness or
cybersecurity savviness
b) Inadequate technology
infrastructure
c) Insufficient budget allocation
d) Lack of skilled personnel
5. How does an organization benefit when individuals at all
levels understand the importance of information security?
a)
b) Enhanced reputation and
operations
c) Reduced risk and fewer security incidents
d) Improved financial performance
6. What is the goal of information security governance in
relation to the security strategy?
a) Contribution to the
fulfillment of the security strategy
b) Alignment with business
objectives only
c) Development of new security
strategies
d) Separate from the business
strategy
7. Where does governance begin in an organization's security
program?
a)
b) Top-level strategic objectives
c) Council members or
commissioners
d) Middle management's
responsibilities
8. What is the relationship between information security
governance and IT governance?
a) Information security
governance is completely independent of IT governance.
b) IT governance is the
foundation for effective information security governance.
c) Information security
governance has no impact on IT governance.
d) IT governance is solely
responsible for information security governance.,
9. What is the importance of establishing effective
governance programs for organizations?
a) To achieve desired and
documented business outcomes
b) To eliminate the need for IT
governance
c) To separate IT governance from
information security governance
d) To minimize the role of
participants in governance activities
10. How are IT governance and information security
governance typically related in organizations?
a) They operate independently
without any overlap.
b) They have separate governance
bodies and participants.
c) Many issues span both IT and
security governance.
d) Information security governance
supersedes IT governance.
Comments
Post a Comment