exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 626 discussion

Actual exam question from Isaca's CISM
Question #: 626
Topic #: 1
[All CISM Questions]

Which of the following is the MOST important factor of a successful information security program?

  • A. The program follows industry best practices.
  • B. The program is based on a well-developed strategy.
  • C. The program is focused on risk management.
  • D. The program is cost-efficient and within budget.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CarlLimps
Highly Voted 1 year, 4 months ago
Selected Answer: B
B - The program is based on a well-developed strategy. That strategy also follows the business strategy.
upvoted 10 times
...
CISSPST
Highly Voted 9 months, 3 weeks ago
Selected Answer: B
Please refer to ISACA Review manual Page 142, 3.1.2: ‘Three elements are essential to ensure successful security program design, implementation and ongoing management: 1. The program must demonstrate execution of a well-developed information security strategy that is closely aligned with and supports organizational objectives. 2nd is management & stakeholder support 3rd is metrics Risk management output is used in development of strategy; IS program being the project plan for implementation strategy.
upvoted 7 times
...
shogun1204
Most Recent 1 month, 2 weeks ago
Selected Answer: C
A successful information security program is risk-driven, ensuring resources are focused on protecting the organization against the most relevant threats. CISM emphasizes that risk management is the core discipline underpinning all security efforts. While strategy, best practices, and budget control are important, managing risk effectively is paramount to achieving security objectives aligned with business goals.
upvoted 2 times
...
bradseth
9 months, 2 weeks ago
Selected Answer: C
C for sure
upvoted 2 times
...
koala_lay
9 months, 3 weeks ago
Selected Answer: C
The MOST important factor of a successful information security program is C. The program being focused on risk management. While all the options mentioned are important, a risk-focused approach is crucial in effectively protecting information assets. By identifying and assessing risks, organizations can prioritize their efforts and allocate resources accordingly to mitigate potential threats. This helps in ensuring the confidentiality, integrity, and availability of sensitive information, which are essential for a successful information security program.
upvoted 2 times
...
6and0
10 months ago
Selected Answer: B
Wouldn't a well-developed strategy take risk management into consideration?
upvoted 1 times
...
Kunzle
10 months, 1 week ago
Selected Answer: C
This option is the most central to the purpose of information security. Risk management ensures that the organization identifies, assesses, and appropriately mitigates threats and vulnerabilities relevant to its operations and objectives.
upvoted 2 times
...
oluchecpoint
10 months, 1 week ago
Selected Answer: C
C. The program is focused on risk management. Risk management is arguably the most important factor of a successful information security program. While the other options are also important, they often tie back to effective risk management
upvoted 2 times
...
wickhaarry
11 months, 3 weeks ago
D. The program is cost-efficient and within budget
upvoted 1 times
...
richck102
1 year ago
B. The program is based on a well-developed strategy.
upvoted 1 times
...
mad68
1 year, 2 months ago
Selected Answer: C
From the ISACA CISM exam perspective, the MOST important factor of a successful information security program is option C: The program is focused on risk management. While all the options mentioned are important considerations for a successful information security program, focusing on risk management is paramount. Risk management is a fundamental aspect of information security as it involves identifying, assessing, and mitigating risks to protect the organization's information assets.
upvoted 6 times
...
meelaan
1 year, 3 months ago
Selected Answer: D
Anybody D?
upvoted 3 times
...
CarlPTY07
1 year, 4 months ago
Selected Answer: C
After management commitment, the most important factor is the Risk management.
upvoted 3 times
...
Souvik124
1 year, 5 months ago
While all the factors are important, the MOST important factor of a successful information security program is that it is focused on risk management. An effective information security program should be designed to identify, assess, and manage risks to the organization's information and assets. This includes identifying potential threats, assessing their likelihood and potential impact, and implementing appropriate controls to reduce risks to an acceptable level. Without a focus on risk management, an information security program may not effectively address the most critical risks to the organization, which could lead to significant security incidents and potential harm to the organization.
upvoted 1 times
...
bambs
1 year, 5 months ago
Selected Answer: A
Definitely A
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...