Isaca CISM Practice Test - Questions Answers, Page 80
List of questions
Related questions
Which of the following should an information security manager do NEXT after creating a roadmap to execute the strategy for an information security program?
A.
Obtain consensus on the strategy from the executive board.
B.
Review alignment with business goals.
C.
Define organizational risk tolerance.
D.
Develop a project plan to implement the strategy.
Which of the following is the MOST effective way to determine the alignment of an information security program with the business strategy?
A.
Evaluate the results of business continuity testing.
B.
Review key performance indicators (KPIs).
C.
Evaluate the business impact of incidents.
D.
Engage business process owners.
Which of the following is the PRIMARY objective of information asset classification?
A.
Vulnerability reduction
B.
Compliance management
C.
Risk management
D.
Threat minimization
Question