Certified Information Security Manager

ISACA_CISM
ProfessionalVersion 2024.1Official exam guide โ†—

Ready to test yourself?

A timed, blueprint-proportional exam drawn fresh from this bank โ€” with a per-domain score report.

๐Ÿ”’ Unlock the simulation โ†’

๐Ÿ”“ Free preview: showing 10 of 150 questions. Unlock the full bank โ€” every question, explanation, and reference.

Unlock all 150 questions โ†’

10 questions across 4 topics. Choose an answer for each question, then check it to see the correct answer and explanation.

Filter by topic

10 questions in Information Security Governance

D1_GOVERNANCE

Information Security Governance

10 questions in topic

Governance structures and reporting lines, security strategy and desired state, policy hierarchy, roles and ownership, the business case for security, culture, and professional ethics.

1
Single choice~110s

A newly appointed CISO inherits a security function widely regarded by the business as an obstacle to delivery. Which action will MOST improve the function's effectiveness over the following year?

2
Single choice~110s

The board asks the CISO whether the enterprise is 'secure enough'. Which response BEST reflects sound governance?

3
Single choice~110s

An enterprise has an approved security strategy, an executive sponsor, and adequate funding, yet initiatives repeatedly stall in delivery. Which cause is MOST likely?

4
Single choice~110s

Two business units interpret the same security standard differently, each believing itself compliant. What does this MOST directly indicate?

5
Single choice~110s

A CISO reporting to the CIO is repeatedly asked to soften findings before they reach the risk committee. Which action is MOST appropriate?

6
Single choice~110s

An enterprise's security policy has been approved by the board but not translated into standards or procedures. What is the MOST significant consequence?

7
Single choice~110s

During budget planning the CFO asks why the security budget should grow when the enterprise has had no breaches. Which response is MOST appropriate?

8
Single choice~110s

An enterprise formally documents that the business owns security risk, yet in practice every security decision is escalated to the CISO. Which is the MOST likely underlying cause?

9
Single choice~110s

Which situation represents the MOST serious weakness in an otherwise mature security governance structure?

10
Single choice~110s

An enterprise operating in a lightly regulated sector adopts the security requirements of a heavily regulated one. Which concern is MOST significant?