exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 632 discussion

Actual exam question from Isaca's CISM
Question #: 632
Topic #: 1
[All CISM Questions]

Which of the following is MOST important for building a robust information security culture within an organization?

  • A. Mature information security awareness training across the organization
  • B. Security controls embedded within the development and operation of the IT environment
  • C. Senior management approval of information security policies
  • D. Strict enforcement of employee compliance with organizational security policies
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CarlLimps
Highly Voted 1 year, 10 months ago
Selected Answer: C
I like C - Senior management approval of information security policies. This is stated over and over again in the CISM book, getting leadership buy in. My two cents.
upvoted 9 times
ddharia94
1 year, 6 months ago
correct. but not used to build a culture
upvoted 3 times
Thavee
9 months ago
Culture= Governance
upvoted 1 times
...
...
...
Thavee
Most Recent 9 months ago
Selected Answer: A
Unclear question. What type of policies the senior management approved? FIrewall? Risk response plan? nooooo... It would be C, if the approval is for business objectives. The word culture (governance) is much broader than policies.
upvoted 1 times
...
yottabyte
9 months, 4 weeks ago
Selected Answer: C
No Money, No awareness program, Senior Management Buy In comes first. so C comes before A. A is critical but C is the entry ticket to the game.
upvoted 1 times
...
Marcovic00
1 year, 1 month ago
Selected Answer: A
i went with C first, but then after a little thinking having policies enforced doesnt promote for a culture, it is training and awareness that does and changes the mindset
upvoted 1 times
...
oluchecpoint
1 year, 4 months ago
Selected Answer: C
Option C
upvoted 1 times
...
AaronS1990
1 year, 4 months ago
Selected Answer: A
Whilst C certainly has its uses A will have more of an influence over the company culture
upvoted 1 times
...
richck102
1 year, 6 months ago
A. Mature information security awareness training across the organization
upvoted 2 times
...
wello
1 year, 7 months ago
Selected Answer: A
A. Mature information security awareness training across the organization Having senior management approve policies is not sufficient for building a culture.
upvoted 3 times
...
Az900500
1 year, 7 months ago
Selected Answer: A
Security culture is dependent on employee awareness and acceptance . Not all employee reads and understand policy even when enforced but through training and awareness understanding and abiding with policy becomes easier and practical
upvoted 3 times
...
Gr3yGh0sT
1 year, 8 months ago
Selected Answer: A
Leaning towards A on this one. The issue with C is that it references just the approval for the policies. For management buy in to be effective, it has to be total support of the entire security program, not just a stamp of approval on the policy documents. However, a robust training program fosters a security culture where everyone in the organization understands the importance of security and takes steps to protect the organization's data and systems.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...