exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 988 discussion

Actual exam question from Isaca's CISM
Question #: 988
Topic #: 1
[All CISM Questions]

Which of the following MUST be established to maintain an effective information security governance framework?

  • A. Security controls automation
  • B. Change management processes
  • C. Security policy provisions
  • D. Defined security metrics
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CISSPST
Highly Voted 1 year, 9 months ago
Selected Answer: C
Policies are the statement of management intent and are at the core of governance. Without policies anything the metrics measure would be irrelevant.
upvoted 5 times
...
arafatms2000
Most Recent 1 year ago
Selected Answer: D
Defined security metrics
upvoted 2 times
...
Marcelus1714
1 year, 4 months ago
Selected Answer: D
Defined security metrics.
upvoted 2 times
...
Soleandheel
1 year, 7 months ago
C. Security policy provisions
upvoted 3 times
...
koala_lay
1 year, 8 months ago
Selected Answer: C
Security policy provisions outline the rules and guidelines for ensuring the confidentiality, integrity, and availability of information within an organization. These provisions help establish the overall direction and goals of the information security program. They provide a framework for implementing security controls, defining security metrics, and managing changes in a consistent and controlled manner.
upvoted 4 times
...
richck102
1 year, 8 months ago
Selected Answer: D
D. Defined security metrics
upvoted 1 times
richck102
1 year, 8 months ago
C. Security policy provisions
upvoted 2 times
...
...
oluchecpoint
1 year, 9 months ago
Selected Answer: C
C. Security policy provisions Establishing security policy provisions is a fundamental requirement for maintaining an effective information security governance framework. Security policies define the organization's approach to managing security and provide guidelines for protecting information and assets. These policies cover various aspects of information security, including data protection, access control, incident response, and compliance requirements. Without clear and well-defined security policy provisions, it is challenging to ensure a consistent and comprehensive approach to information security within an organization.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...