CISM (CISM) General 2 — Questions and Answers
Question 1: An information security manager discovers that a business unit is using an unapproved cloud service to store sensitive customer data. What is the BEST first action?
- Immediately shut down the service
- Conduct a risk assessment of the cloud service (Correct answer)
- Report the business unit to executive management
- Block network access to the cloud provider
Correct answer: Conduct a risk assessment of the cloud service
A risk assessment determines the actual exposure before taking disruptive action, enabling an informed and proportional response.
Question 2: Which metric BEST demonstrates the effectiveness of an information security awareness training program?
- Number of employees who completed training
- Reduction in security incidents caused by human error (Correct answer)
- Cost of delivering the training program
- Number of training modules available
Correct answer: Reduction in security incidents caused by human error
Outcome-based metrics like reduced human-error incidents directly measure whether training changed behavior, not just participation.
Question 3: A CISM candidate is reviewing the organization's information security governance structure. Which element is MOST critical to effective governance?
- Dedicated security operations center
- Executive management accountability and oversight (Correct answer)
- Automated vulnerability scanning tools
- Third-party penetration testing schedule
Correct answer: Executive management accountability and oversight
Governance requires senior leadership accountability; without it, security strategy lacks authority and resources.
Question 4: When aligning information security strategy with business objectives, the security manager should PRIMARILY focus on:
- Implementing the latest security technologies
- Ensuring compliance with all regulations
- Enabling business goals while managing risk to acceptable levels (Correct answer)
- Eliminating all identified vulnerabilities
Correct answer: Enabling business goals while managing risk to acceptable levels
Security strategy must support business objectives by balancing risk management with operational enablement rather than simply enforcing controls.
Question 5: An organization is about to launch a new product that processes health information. When should the information security manager FIRST be engaged?
- During user acceptance testing
- After the product is developed
- During initial project planning and design (Correct answer)
- When the product is ready for deployment
Correct answer: During initial project planning and design
Security-by-design requires engaging the security function at project inception to embed controls rather than retrofit them.
Question 6: A security manager is presenting the value of information security to the board. Which approach is MOST effective?
- Demonstrate technical vulnerability details from the last penetration test
- Present security metrics tied to business risk and financial impact (Correct answer)
- Show the number of security incidents blocked last quarter
- Explain the technical architecture of security controls
Correct answer: Present security metrics tied to business risk and financial impact
Board-level communication requires translating security activities into business risk and financial terms that resonate with executives.
Question 7: Which of the following BEST describes the relationship between information security policy and procedures?
- Procedures define what must be done; policies describe how to do it
- Policies define what must be done; procedures describe how to do it (Correct answer)
- Policies and procedures are interchangeable documents
- Procedures are written by executives; policies by technical staff
Correct answer: Policies define what must be done; procedures describe how to do it
Policies establish high-level requirements and intent, while procedures provide step-by-step instructions for implementing those requirements.
An information security manager discovers that a business unit is using an unapproved cloud service to store sensitive customer data.
What is the BEST first action?