Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 602 discussion

Actual exam question from Isaca's CISM
Question #: 602
Topic #: 1
[All CISM Questions]

Which of the following is MOST important to ensure ongoing senior management commitment to an organization’s information security strategy?

  • A. Effective and reliable security reporting
  • B. A well-defined information security control framework
  • C. A detailed and documented business impact analysis (BIA)
  • D. Strategic alignment to an industry framework
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Booict
2 months, 3 weeks ago
Selected Answer: A
A for me
upvoted 1 times
...
Thavee
7 months, 1 week ago
Selected Answer: C
The question responded to many answers. It said MOST IMPORTANT TO ENSURE THE ONGOING SENIOR MANAGEMENT COMMITMENT. Asking back, what Senior Management is expecting from such information security STRATEGY then. Money or good reliable report. (reliable report in what senses --> technical, occurrences, or bla bla bla. What if the report is rubbished, talking about stars and sky. That is not benefiting at all even if the report is reliable (trust-able). I believed the Senior management focuses on business objectives that are inline with BIA. If my guess is correct, the answer is C. However, if the report is well done that benefits, obviously, the business objectives, no interpretation is need for the senior management who does not know IT 101, the answer would be A then.
upvoted 1 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: A
A. Effective and reliable security reporting Effective and reliable security reporting allows senior management to understand the current state of the organization's information security, the effectiveness of security controls, and the potential risks and threats facing the organization. It provides them with the information they need to make informed decisions and prioritize investments in information security. Without accurate and up-to-date reporting, senior management may not have the visibility they need to stay committed to the organization's security strategy.
upvoted 1 times
...
richck102
1 year, 4 months ago
A. Effective and reliable security reporting
upvoted 1 times
...
meelaan
1 year, 7 months ago
Selected Answer: C
Why not C?
upvoted 1 times
dark_3k03r
1 year, 7 months ago
Business Impact Analysis (BIA) is the bases for the RTO for BCP and it is also used for classifications in IRP. But A is 100% security that's why. Not to mention the keyword is "ongoing" a BIA is not continuous, it's done quarterly. The only continuous answer is (A).
upvoted 1 times
Thavee
7 months, 1 week ago
nothing about continuous, ongoing senior management commitment in this scenario means "on going support of the security strategy". if the IT team messed up, no more supports, no more money, and no more other resources.
upvoted 1 times
...
...
...
CarlLimps
1 year, 8 months ago
Selected Answer: A
A for me too.
upvoted 2 times
...
Broesweelies
1 year, 9 months ago
Selected Answer: A
A it is.
upvoted 4 times
...
MyKasala
1 year, 10 months ago
Selected Answer: A
I think A
upvoted 3 times
...
Ziggybooboo
1 year, 11 months ago
A for me
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...