ExamGecko
Question list
Search
Search

Question 587 - CISM discussion

Report
Export

What should an information security manager verify FIRST when reviewing an information asset management program?

A.
System owners have been identified.
Answers
A.
System owners have been identified.
B.
Key applications have been secured.
Answers
B.
Key applications have been secured.
C.
Information assets have been classified.
Answers
C.
Information assets have been classified.
D.
Information assets have been inventoried.
Answers
D.
Information assets have been inventoried.
Suggested answer: C

Explanation:

According to the CISM Review Manual, information asset classification is the first step in an information asset management program, as it provides the basis for determining the level of protection required for each asset. System owners, key applications and information asset inventory are subsequent steps that depend on the classification of the assets.

Reference= CISM Review Manual, 27th Edition, Chapter 1, Section 1.4.2, page 381.

asked 01/10/2024
Veridjan Hoxha
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first