CISM Domain 1 Questions Set-1: INFORMATION SECURITY GOVERNANCE

1. Which processes are typically included in information security governance?

a) Personnel management, sourcing, and change management

b) Configuration management, access management, and business continuity planning

c) Risk management, vulnerability management, and incident management

d) All of the above

2. What is a key component of information security governance?

a) Continuous improvement of security processes

b) Effective organization structure and role definition

c) Balanced scorecard and metrics monitoring

d) All of the above

3. Why do organizations that lack information security face a business problem?

a) Poor business continuity planning

b) Inadequate technology solutions

c) Insufficient personnel management

d) Lack of understanding and commitment by senior executives

4. What is the main challenge faced by organizations in managing information security at the boardroom level?

a) Lack of awareness or cybersecurity savviness

b) Inadequate technology infrastructure

c) Insufficient budget allocation

d) Lack of skilled personnel

5. How does an organization benefit when individuals at all levels understand the importance of information security?

a) Increased technology infrastructure

b) Enhanced reputation and operations

c) Reduced risk and fewer security incidents

d) Improved financial performance

6. What is the goal of information security governance in relation to the security strategy?

a) Contribution to the fulfillment of the security strategy

b) Alignment with business objectives only

c) Development of new security strategies

d) Separate from the business strategy

7. Where does governance begin in an organization's security program?

a) Policies and procedures

b) Top-level strategic objectives

c) Council members or commissioners

d) Middle management's responsibilities

8. What is the relationship between information security governance and IT governance?

a) Information security governance is completely independent of IT governance.

b) IT governance is the foundation for effective information security governance.

c) Information security governance has no impact on IT governance.

d) IT governance is solely responsible for information security governance.,

9. What is the importance of establishing effective governance programs for organizations?

a) To achieve desired and documented business outcomes

b) To eliminate the need for IT governance

c) To separate IT governance from information security governance

d) To minimize the role of participants in governance activities

10. How are IT governance and information security governance typically related in organizations?

a) They operate independently without any overlap.

b) They have separate governance bodies and participants.

c) Many issues span both IT and security governance.

d) Information security governance supersedes IT governance.


Comments

Popular posts from this blog

CISM Domain 1 Questions Set-3: INFORMATION SECURITY GOVERNANCE

CISM Domain 1 Answers Set-2: INFORMATION SECURITY GOVERNANCE