CISM Information Security Governance 2 — Questions and Answers
Question 1: Which framework is MOST commonly used to establish information security governance in US enterprises?
- PCI DSS
- COBIT (Correct answer)
- OWASP Top 10
- CVE
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is widely used for IT and information security governance in enterprises.
Question 2: When developing a security governance program, a CISM should FIRST:
- Purchase security tools and technologies
- Understand the organization's business strategy and objectives (Correct answer)
- Hire additional security staff
- Conduct a gap analysis of current controls
Correct answer: Understand the organization's business strategy and objectives
Understanding the business strategy ensures that the security governance program is aligned with and supports organizational goals from the outset.
Question 3: Which of the following BEST describes the relationship between IT governance and information security governance?
- They are identical and interchangeable
- Information security governance is a subset of IT governance (Correct answer)
- IT governance reports to information security governance
- They operate independently with no overlap
Correct answer: Information security governance is a subset of IT governance
Information security governance is a subset of IT governance, which itself is a component of overall corporate governance.
Question 4: A CISM is presenting a security governance roadmap to the CEO. The presentation should PRIMARILY focus on:
- Technical vulnerability details and patch timelines
- Security risk in terms of business impact and strategic alignment (Correct answer)
- Specific firewall configurations and network diagrams
- Number of security incidents detected last quarter
Correct answer: Security risk in terms of business impact and strategic alignment
Executive presentations should frame security governance in business terms, focusing on risk, impact, and alignment with organizational strategy.
Question 5: Which of the following is a KEY output of a mature information security governance program?
- Zero security incidents
- Security metrics aligned to business objectives (Correct answer)
- 100% patch compliance
- Elimination of all third-party vendors
Correct answer: Security metrics aligned to business objectives
A mature governance program produces meaningful security metrics that are tied to and measured against business objectives, demonstrating value to leadership.
Question 6: Separation of duties in security governance is PRIMARILY intended to:
- Speed up security approvals
- Reduce the risk of fraud and error by distributing responsibilities (Correct answer)
- Decrease the number of security staff needed
- Automate compliance reporting
Correct answer: Reduce the risk of fraud and error by distributing responsibilities
Separation of duties distributes critical responsibilities so that no single person can complete a high-risk task alone, reducing the risk of fraud or error.
Which framework is MOST commonly used to establish information security governance in US enterprises?