Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 32 discussion

Actual exam question from Isaca's CISM
Question #: 32
Topic #: 1
[All CISM Questions]

Which of the following is the BEST way for an organization to determine the maturity level of its information security program?

  • A. Review the results of information security awareness testing.
  • B. Validate the effectiveness of implemented security controls.
  • C. Benchmark the information security policy against industry standards.
  • D. Track the trending of information security incidents.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
k4d4v4r
Highly Voted 2 years, 1 month ago
Remember that B is basically the gap analysis needed
upvoted 10 times
...
alt_coffey
Most Recent 1 month, 2 weeks ago
Selected Answer: B
Choosing B since maturity is all about the process of security review and control
upvoted 2 times
...
Shervi
1 month, 3 weeks ago
Selected Answer: C
It’s c. What if they only have 2 controls that work really well, but miss the other 300? One of the ways to assess an organisations maturity is to assess the security policy. C does just that.
upvoted 2 times
...
greeklover84
2 months ago
Selected Answer: B
I think it is B.
upvoted 1 times
...
Josef4CISM
2 months, 3 weeks ago
I hesitated between B and C and decided to pick B, because: Policies happen on paper, the actual doing and assessment of the situation at hand can only be done by assessing the state of security controls. Therefore B.
upvoted 2 times
...
ElDirec
9 months, 1 week ago
Selected Answer: C
I see the discussion here, and validate against AI, which chooses B. However, I think this is more of a textbook question, the word "maturity" is what I keep hearing candidates that have CISM or CISSP certs use in their interview answers. I think COMPTIA is looking to see that we take Frameworks and standrads into account, after all, this is more of a management cert. I'm going with C thinking this is more of a "BIG WORD" that needs to be used, even though in real life, you wanna test your controls work as in in B
upvoted 2 times
...
e891cd1
9 months, 3 weeks ago
we also have to take in consideration it says "Best" and what maturity means in the context of a security program. It means how well is this program developed and how well it is at handling different situations. The "best" way to test that would be to validate the controls rather than comparing the controls to best practice.
upvoted 2 times
...
Cisco900
10 months, 1 week ago
The correct answer is B. We assess maturity of the program through metrics associated to the implemented controls. Training and awareness results are only part of the metrics. There are others like IT team performance, vulnerability remediation performance, etc.
upvoted 3 times
...
learntstuff
11 months, 1 week ago
Selected Answer: C
C. CISM book from mike chappel. maturity models asses an org. against industry best practices.
upvoted 2 times
Cisco900
10 months, 1 week ago
That's what maturity assessment achieves, not how to determine them.
upvoted 1 times
...
...
Cyberbug2021
12 months ago
Selected Answer: B
Benchmark the information security policy against industry standards: Benchmarking the policy against industry standards ensures that it aligns with recognized security practices. However, it doesn't guarantee that the policy is actually being implemented and enforced effectively.
upvoted 1 times
...
Viperhunter
12 months ago
Selected Answer: C
Benchmarking the information security policy against industry standards is a comprehensive approach that allows organizations to assess the maturity of their information security program in comparison to established best practices and industry benchmarks. This involves evaluating the organization's policies, processes, and controls against recognized standards such as ISO/IEC 27001, NIST Cybersecurity Framework, or other relevant frameworks. While options like reviewing the results of information security awareness testing (option A), validating the effectiveness of implemented security controls (option B), and tracking the trending of information security incidents (option D) are important activities, benchmarking against industry standards provides a broader and more systematic evaluation of the overall maturity of the information security program.
upvoted 3 times
...
Learner76
1 year ago
Selected Answer: C
I will say it is C. You will have to Benchmark against something to know where or how far (mature) your program is at
upvoted 2 times
...
Perseus_68
1 year, 1 month ago
C is not correct because it says benchmarking the security "policy", this is not at all comprehensive. If it said security "program". The best answer provided for the question is not always the best way.
upvoted 2 times
...
Azurefox79
1 year, 3 months ago
Selected Answer: C
Its C. The word "Maturity" is why its C and not B. Maturity is not arbitrarily defined against your own program, its defined by the industry such as CMMC L1, 3 or 5. Initial, repeatable, defined, managed, Optimized. The industry dictates your maturity level, not the effectiveness of controls. For example, having a heroic team that ad-hoc responds to incidents may be incredibly effective but if they dont have clear policies and procedures their effectives does not translate into a mature process.
upvoted 2 times
Hugo1717
1 year, 2 months ago
Its B. Its not because your security policy is nice that it means you are mature.
upvoted 1 times
...
...
richck102
1 year, 6 months ago
B. Validate the effectiveness of implemented security controls.
upvoted 1 times
richck102
1 year, 6 months ago
C. Benchmark the information security policy against industry standards.
upvoted 2 times
[Removed]
1 year, 5 months ago
Your risk apetite might be lower or higher than industry standards
upvoted 2 times
Azurefox79
1 year, 3 months ago
Maturity level is agnostic of risk appetite. Its defined by the industry such as CMM levels.
upvoted 2 times
...
...
...
...
CarlPTY07
1 year, 8 months ago
Selected Answer: B
The question refers to the validation of the effectiveness of our controls, hence the B is the right one.
upvoted 4 times
Azurefox79
1 year, 3 months ago
No it is not about the effectiveness of security controls its about the maturity. Maturity is not arbitrary, its based on industry standards like CMM.
upvoted 1 times
...
...
vavofa5697
1 year, 9 months ago
Selected Answer: C
A benchmark, such as an industry standard or best practices framework, always determines the maturity level.
upvoted 4 times
dark_3k03r
1 year, 7 months ago
The security policy is a written document and is not necessarily what is implemented. In fact most policies are aspirational in nature as a result 'C' is not the correct result. While 'B' there is no if or else about it. It either performs or it doesn't. It also says the level at which it operates.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...