exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 97 discussion

Actual exam question from Isaca's CISM
Question #: 97
Topic #: 1
[All CISM Questions]

Which of the following is the PRIMARY purpose of establishing an information security governance framework?

  • A. To proactively address security objectives
  • B. To reduce security audit issues
  • C. To enhance business continuity planning
  • D. To minimize security risks
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Abhey
Highly Voted 1 year, 2 months ago
Selected Answer: A
The PRIMARY purpose of establishing an information security governance framework is to proactively address security objectives. The framework provides a structure for aligning information security activities with business objectives, defining roles and responsibilities, and ensuring that information security risks are managed appropriately.
upvoted 5 times
...
Vishalgupta26
Most Recent 3 weeks, 6 days ago
Selected Answer: A
An information security governance framework is designed to provide a structured approach to managing information security in alignment with business objectives. It helps ensure that security risks are properly identified, managed, and mitigated, while also ensuring that the organization's security policies, procedures, and controls support its strategic goals. This proactive approach enables the organization to effectively manage security and align it with broader business objectives.
upvoted 1 times
...
helg420
2 months ago
Selected Answer: A
A. To proactively address security objectives The PRIMARY purpose of establishing an information security governance framework is to proactively address security objectives. This involves establishing and maintaining a framework and supporting processes to ensure that information security strategies align with business objectives and that risks are managed effectively. By doing so, it provides a structured approach to safeguarding digital assets, processes, and systems from cyber threats, while ensuring compliance with applicable laws and regulations. Information security governance frameworks are designed to define the organization's security objectives, identify and assess risks, and develop policies and procedures. This proactive approach to addressing security objectives helps organizations not only meet their regulatory and compliance requirements but also manage and mitigate potential security risks before they can impact the business.
upvoted 2 times
...
oluchecpoint
5 months, 1 week ago
Selected Answer: A
A. To proactively address security objectives The PRIMARY purpose of establishing an information security governance framework is to proactively address security objectives. Information security governance helps an organization define its security goals, establish policies and procedures, allocate resources, and create a structured approach to managing and improving security. It is focused on ensuring that the organization's security measures are aligned with its overall business objectives and that it takes a proactive rather than reactive approach to security. While reducing security audit issues, enhancing business continuity planning, and minimizing security risks are important aspects of information security governance, they are typically secondary to the primary goal of proactively addressing security objectives.
upvoted 1 times
...
Cyberbug2021
7 months, 3 weeks ago
Selected Answer: A
The correct answer is A. To proactively address security objectives. An information security governance framework provides a structured approach to managing information security risks and ensuring that security is aligned with the organization's overall business objectives. It helps organizations proactively address security challenges, rather than reacting to incidents after they occur.
upvoted 1 times
...
Viperhunter
7 months, 3 weeks ago
Selected Answer: A
An information security governance framework provides a structured approach to managing and implementing information security practices within an organization. It involves defining roles, responsibilities, and processes to proactively address security objectives and ensure that information security aligns with the overall business goals and strategies. While reducing security audit issues, enhancing business continuity planning, and minimizing security risks are important outcomes of effective information security governance, the overarching goal is to establish a systematic and strategic approach to managing information security within the organization.
upvoted 1 times
...
sphenixfire
10 months, 1 week ago
Selected Answer: A
CISM AIO 2nd, Information Governance Frameworks and Standards, last part
upvoted 1 times
...
oluchecpoint
10 months, 2 weeks ago
A. To proactively address security objectives The PRIMARY purpose of establishing an information security governance framework is to proactively address security objectives. Information security governance helps an organization define its security goals, establish policies and procedures, allocate resources, and create a structured approach to managing and improving security. It is focused on ensuring that the organization's security measures are aligned with its overall business objectives and that it takes a proactive rather than reactive approach to security. While reducing security audit issues, enhancing business continuity planning, and minimizing security risks are important aspects of information security governance, they are typically secondary to the primary goal of proactively addressing security objectives.
upvoted 1 times
...
richck102
1 year, 1 month ago
D. To minimize security risks
upvoted 1 times
...
dark_3k03r
1 year, 2 months ago
Selected Answer: A
The primary purpose of an infosec governance framework is to meet the security objectives of the organization. Proactive is nice, but it's just meeting those objectives. Rationale: (B) To reduce security audit issues is a byproduct, not the driver. If you manage the security objectives this will just happen. (C) To enhance business continuity planning is a byproduct, not the driver. If you manage the security objectives this will just happen. (D) To minimize security risks, is a byproduct, not the driver. If you manage the security objectives this will just happen.
upvoted 4 times
...
dedfef
1 year, 3 months ago
Selected Answer: D
d is the correct answer
upvoted 2 times
...
Saj194
1 year, 4 months ago
Selected Answer: D
Primary purpose is to minimize risk.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago