exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 357 discussion

Actual exam question from Isaca's CISM
Question #: 357
Topic #: 1
[All CISM Questions]

Which of the following is MOST important to the effectiveness of an information security program?

  • A. Organizational culture
  • B. Risk management
  • C. IT governance
  • D. Security metrics
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dark_3k03r
Highly Voted 1 year, 7 months ago
Selected Answer: B
The most important is (B) risk management as this is what identifies, manages, and remediates risks. (i.e. what makes the security program effective. A. Organizational culture - This influences security, but doesn't implement it. C. IT governance - ensures that the program is effective and efficient. But it doesn't align, identify or remediate things. D. Security metrics - security metrics just quantify the effectiveness.
upvoted 9 times
...
e891cd1
Most Recent 6 months, 3 weeks ago
I said C but it would be "A" when i think about it since "C" would be part of "A". Organization culture will include Governance.
upvoted 2 times
...
afoo1314
7 months, 2 weeks ago
Selected Answer: A
If organisation does not support, they won't support proper risk management.
upvoted 2 times
...
oluchecpoint
9 months, 2 weeks ago
Selected Answer: A
Option A
upvoted 2 times
...
Uncle_Lucifer
11 months, 1 week ago
Selected Answer: A
Culture is the main foundation. --> A
upvoted 3 times
...
King21
12 months ago
Risk management is a subset of organizational culture
upvoted 2 times
...
Soleandheel
12 months ago
I was stuck between options A and B but ended up going with A. Organizational culture because organizational culture (Option A) can be considered the foundation upon which effective risk management is built. Without a security-conscious organizational culture that values and supports security practices, risk management efforts may face challenges in gaining full organizational support and compliance. Therefore, A is the best answer here.
upvoted 1 times
...
acf4e9a
1 year ago
Selected Answer: A
Risk management goal is to assess and propose treatment, however, the end acceptance is with respective business units or senior management so the culture would have a huge influence in making appropriate decisions so answer A should be more suitable here.
upvoted 2 times
...
oluchecpoint
1 year, 2 months ago
B. Risk management. Effective risk management is at the core of any robust information security program. It involves identifying, assessing, and mitigating risks to an organization's information assets and systems. Without a well-developed risk management process, it becomes challenging to make informed decisions about where to allocate resources, what security controls to implement, and how to respond to security incidents.
upvoted 1 times
oluchecpoint
9 months, 2 weeks ago
Option A
upvoted 1 times
...
...
[Removed]
1 year, 3 months ago
Selected Answer: A
The CISM Review Manual, 27th Edition, on page 27, states that "The influence of organizational culture on the information security governance framework is significant. An organization's culture influences the behavior of its employees. This, in turn, has an effect on the security of information within the organization. A security-aware culture reduces the likelihood of incidents occurring and increases the likelihood of incidents being reported and dealt with appropriately when they do occur."
upvoted 2 times
SilverFox
1 year ago
No such quote in CISA 27th or CISM 16th/15th. However CISM 15th Ed in Section 2.3 does state importance of Organizational Culture on Effective Risk Management and how the latter can be undermined by the influence of the former. So I will go with A.
upvoted 1 times
...
...
[Removed]
1 year, 4 months ago
Selected Answer: A
A is most important in effectivness.
upvoted 3 times
...
CISSPST
1 year, 4 months ago
From policy compliance to user acceptance, intentional threats to accidental errors, human factor is both a major risk and the greatest strength in information security. Therefore, organizational culture which is a product of shared beliefs, assumptions and behaviors of people, is easily the most influential factor for the success of an information security program.
upvoted 1 times
...
richck102
1 year, 4 months ago
B. Risk management
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: B
Risk management is at the core of an effective information security program. It involves identifying, assessing, and prioritizing risks to the organization's information assets. By understanding the risks, organizations can make informed decisions on allocating resources, implementing controls, and prioritizing security initiatives. Risk management ensures that security efforts are focused on addressing the most significant and relevant risks, leading to a more effective security program overall.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago