CISM Information Security Program Development 2 — Questions and Answers
Question 1: A CISM is implementing a security control framework. Which of the following is MOST important when selecting a framework?
- It must be mandated by a government agency
- It should align with the organization's risk profile and industry requirements (Correct answer)
- It must be the most recently published framework available
- It should be the most widely adopted framework globally
Correct answer: It should align with the organization's risk profile and industry requirements
Framework selection should be based on alignment with the organization's specific risk profile, regulatory environment, and industry context.
Question 2: Which of the following BEST describes a 'defense-in-depth' strategy in an information security program?
- Deploying a single, highly capable security platform
- Relying exclusively on perimeter defenses such as firewalls
- Implementing multiple layers of controls so that failure of one does not expose assets (Correct answer)
- Focusing all security investment on the most critical assets only
Correct answer: Implementing multiple layers of controls so that failure of one does not expose assets
Defense-in-depth uses multiple overlapping layers of controls so that no single point of failure can compromise security.
Question 3: When building a security program, which of the following activities should be performed on a CONTINUOUS basis?
- Initial risk assessment only
- Employee onboarding security briefings only
- Monitoring of controls effectiveness and emerging threats (Correct answer)
- Annual policy review and update cycle
Correct answer: Monitoring of controls effectiveness and emerging threats
Continuous monitoring of control effectiveness and the threat landscape ensures the security program remains relevant and effective as conditions change.
Question 4: A CISM is developing a vulnerability management program. The FIRST step should be:
- Deploying automated scanning tools across all systems
- Defining the scope, assets, and criticality tiers to be covered (Correct answer)
- Establishing a patch deployment schedule for all systems
- Negotiating a vulnerability disclosure policy with vendors
Correct answer: Defining the scope, assets, and criticality tiers to be covered
Defining the scope, assets covered, and their criticality ensures the vulnerability management program is structured and resources are focused appropriately.
Question 5: Which of the following BEST supports a 'security by design' approach in program development?
- Performing security assessments only after systems are deployed
- Integrating security requirements into the project lifecycle from inception (Correct answer)
- Purchasing security add-ons for existing systems after deployment
- Relying on vendors to build security into their products
Correct answer: Integrating security requirements into the project lifecycle from inception
Security by design integrates security requirements early in the system development lifecycle, reducing cost and complexity compared to retrofitting controls later.
Question 6: A CISM is establishing a vendor risk management program. The MOST critical first step is to:
- Require all vendors to sign a confidentiality agreement
- Identify and inventory all third-party relationships and their data access levels (Correct answer)
- Deploy security monitoring tools on all vendor networks
- Conduct on-site audits of all vendors annually
Correct answer: Identify and inventory all third-party relationships and their data access levels
Identifying and inventorying all third-party relationships and their level of access provides the foundation for assessing and managing vendor risk effectively.
A CISM is implementing a security control framework.
Which of the following is MOST important when selecting a framework?