Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 35 discussion

Actual exam question from Isaca's CISM
Question #: 35
Topic #: 1
[All CISM Questions]

The chief information security officer (CISO) has developed an information security strategy, but is struggling to obtain senior management commitment for funds to implement the strategy. Which of the following is the MOST likely reason?

  • A. The strategy does not include a cost-benefit analysis.
  • B. There was a lack of engagement with the business during development.
  • C. The strategy does not comply with security standards.
  • D. The CISO reports to the CIO.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alt_coffey
1 month, 2 weeks ago
Selected Answer: A
Best answer is A, cost-benefit. It would be B if the wording was written better, I believe the question may have been more like "the organization was not engaged". But the current way B reads is "there was an external business negotiation, and they were not engaged", but there's no mention of an agreement outside the company
upvoted 2 times
...
greeklover84
2 months ago
Selected Answer: A
since teh CISO is looking for budget to get it approved...he must present the cost/benefit relationship as a mean to convince the Management.
upvoted 1 times
...
shervin2s
8 months, 2 weeks ago
Selected Answer: B
According to the CISM Review Manual, 15th Edition, Page 437, Paragraph 3, the MOST likely reason for the struggle of the chief information security officer (CISO) to obtain senior management commitment for funds to implement the information security strategy is There was a lack of engagement with the business during development.
upvoted 1 times
...
oluchecpoint
9 months, 2 weeks ago
Selected Answer: B
Answer is B To address this issue, the CISO should work on enhancing business engagement, involving key stakeholders in the strategy's development, and clearly demonstrating how the security strategy aligns with and supports the organization's business objectives and risk mitigation.
upvoted 1 times
...
AlexJacobson
11 months, 3 weeks ago
Going with D here. The keyword here is "BEST" so we're looking for an answer that offers the most comprehensive approach. Tabletop exercises are just one way to test BCP/DRP/IR.
upvoted 1 times
...
Viperhunter
12 months ago
Selected Answer: B
The lack of engagement with the business during the development of the information security strategy can lead to a situation where senior management may not fully understand the strategic alignment of security initiatives with business goals. Effective communication and collaboration with key stakeholders in the business are crucial to ensure that the security strategy is seen as integral to the organization's overall objectives and priorities. While the absence of a cost-benefit analysis (option A), non-compliance with security standards (option C), and reporting structure (option D) can be contributing factors, a lack of engagement with the business is often a primary reason for challenges in obtaining commitment and funding for security initiatives.
upvoted 1 times
...
Soleandheel
1 year ago
I go with B. ..............A lack of engagement with the business or a perception that the strategy doesn't align with the organization's goals can have a more significant impact on senior management's decision-making process compared to the absence of a cost-benefit analysis. This one is tricky but you have to think like a CISM.
upvoted 1 times
...
Jess20
1 year ago
A- struggling to obtain senior management commitment for "fund". Cost benefit analysis
upvoted 1 times
...
POWNED
1 year ago
Selected Answer: B
Come on people in what world will a project get approved without a Cost benefit analysis. Its not going to happen therefore the obvious answer here is B.
upvoted 2 times
...
Learner76
1 year ago
Selected Answer: A
I see the keyword as "Fund". Without a cost benefit analysis how can the spending be approved?
upvoted 1 times
...
Perseus_68
1 year, 1 month ago
The scenario - CISO develops a strategy, Senior management (they are from the Business, not executives) resistance, eluding that was done in isolation.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Answer is B To address this issue, the CISO should work on enhancing business engagement, involving key stakeholders in the strategy's development, and clearly demonstrating how the security strategy aligns with and supports the organization's business objectives and risk mitigation.
upvoted 1 times
...
Azurefox79
1 year, 3 months ago
Selected Answer: B
B. This is the CISM exam and you need to give CISM answers. In the CISM senior management support and engagement trumps everything else and is the ultimate choice.
upvoted 3 times
...
DavoA
1 year, 4 months ago
Selected Answer: A
Cost benefit analysis
upvoted 1 times
...
jennarink13
1 year, 4 months ago
I think A. Regardless if you involve the business or not, they won't buy it if you provided them with a solution without the possible benefits/impact and the relative costs.
upvoted 1 times
jennarink13
1 year, 4 months ago
CBA is part of a business case which justifies the solution. If the solution is not justified and backed up, you won't probably get it approved. Business engagement is important, but you cannot tell Senior Leadership "hey we engaged business stakeholders here, please approve the budget". They will most probably look at the justification of this proposed solution. Additionally, business engagement does not necessarily facilitates CBA activities to be performed.
upvoted 2 times
...
...
Rowlandmarc
1 year, 4 months ago
Selected Answer: A
Cost benefit analysis since the funds are not approved
upvoted 1 times
...
ddharia94
1 year, 5 months ago
Selected Answer: A
Cost benefit analysis since the funds are not approved
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...