exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 581 discussion

Actual exam question from Isaca's CISM
Question #: 581
Topic #: 1
[All CISM Questions]

Which of the following provides the BEST guidance when establishing a security program?

  • A. Risk assessment methodology
  • B. Security audit report
  • C. Information security budget
  • D. Information security framework
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
D2D2
Highly Voted 2 years, 1 month ago
Selected Answer: D
Framework would provide guidance NIST, COBIT, etc...
upvoted 10 times
Ziggybooboo
2 years ago
Agreed
upvoted 4 times
...
...
koala_lay
Most Recent 1 year, 3 months ago
Selected Answer: D
D. Information security framework provides the best guidance when establishing a security program. An information security framework sets out the foundational structure and guidelines for implementing an effective security program. It helps organizations in identifying and addressing potential risks, establishing security controls, and ensuring compliance with industry standards and regulations.
upvoted 3 times
...
richck102
1 year, 6 months ago
D. Information security framework
upvoted 2 times
...
Dravidian
1 year, 8 months ago
Selected Answer: B
Following the framework is a good start if you got nothing to use. Frameworks are very generic guidelines that you tailor to your organizational needs. The question here is the BEST guidance, which to me is the audit report. It tells you where exactly you're lacking and what you need so you can use that in your program and know 100% it's going to address current issues.
upvoted 3 times
Salilgen
10 months, 1 week ago
If that were the case, the audit report would always be the best guide (even when you don't have a security program at all) and frameworks would be of no use. If you have not a security program, what should be the BEST guidance? Framework or audit report? IMO answer is D
upvoted 1 times
...
...
CarlLimps
1 year, 9 months ago
Selected Answer: D
D. Framework provides guidance, always.
upvoted 2 times
...
CarlPTY07
1 year, 10 months ago
Selected Answer: D
Yep, Is D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...