A newly appointed CISO inherits a security function widely regarded by the business as an obstacle to delivery. Which action will MOST improve the function's effectiveness over the following year?
Certified Information Security Manager
ISACA_CISMReady to test yourself?
A timed, blueprint-proportional exam drawn fresh from this bank โ with a per-domain score report.
๐ Free preview: showing 10 of 150 questions. Unlock the full bank โ every question, explanation, and reference.
Unlock all 150 questions โ10 questions across 4 topics. Choose an answer for each question, then check it to see the correct answer and explanation.
Filter by topic
All 10 questions
Information Security Governance
10 questions in topicGovernance structures and reporting lines, security strategy and desired state, policy hierarchy, roles and ownership, the business case for security, culture, and professional ethics.
The board asks the CISO whether the enterprise is 'secure enough'. Which response BEST reflects sound governance?
An enterprise has an approved security strategy, an executive sponsor, and adequate funding, yet initiatives repeatedly stall in delivery. Which cause is MOST likely?
Two business units interpret the same security standard differently, each believing itself compliant. What does this MOST directly indicate?
A CISO reporting to the CIO is repeatedly asked to soften findings before they reach the risk committee. Which action is MOST appropriate?
An enterprise's security policy has been approved by the board but not translated into standards or procedures. What is the MOST significant consequence?
During budget planning the CFO asks why the security budget should grow when the enterprise has had no breaches. Which response is MOST appropriate?
An enterprise formally documents that the business owns security risk, yet in practice every security decision is escalated to the CISO. Which is the MOST likely underlying cause?
Which situation represents the MOST serious weakness in an otherwise mature security governance structure?
An enterprise operating in a lightly regulated sector adopts the security requirements of a heavily regulated one. Which concern is MOST significant?