exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 428 discussion

Actual exam question from Isaca's CISM
Question #: 428
Topic #: 1
[All CISM Questions]

The effectiveness of an information security governance framework will BEST be enhanced if:

  • A. consultants review the information security governance framework
  • B. IS auditors are empowered to evaluate governance activities
  • C. a culture of legal and regulatory compliance is promoted by management
  • D. risk management is built into operational and strategic activities
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Agamennore
8 months ago
Selected Answer: D
The culture (C) Helps but not only in compliance. The best option is "risk management is built into operational and strategic activities"
upvoted 4 times
...
richck102
10 months ago
D. risk management is built into operational and strategic activities
upvoted 3 times
...
Saisharan
10 months, 4 weeks ago
By incorporating risk management into day-to-day operations and long-term strategic planning, organizations can ensure that security risks are identified, assessed, and appropriately addressed. This approach allows for a proactive and systematic approach to managing risks, rather than treating them as isolated incidents or afterthoughts. Option D
upvoted 3 times
...
Broesweelies
1 year, 3 months ago
Selected Answer: D
D. Risk management is built into operational and strategic activities The effectiveness of an information security governance framework will best be enhanced if risk management is built into operational and strategic activities. This means that the organization considers and manages information security risks as part of its day-to-day operations and decision-making processes. When risk management is integrated into organizational activities, it becomes a fundamental part of the organization's culture, and not just an isolated function. This allows the organization to more effectively identify, evaluate, and mitigate information security risks, and to align its information security efforts with its overall business goals and objectives.
upvoted 4 times
...
MyKasala
1 year, 3 months ago
Selected Answer: D
I guess D
upvoted 2 times
...
aokisan
1 year, 4 months ago
Selected Answer: B
audit will enhance framework.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago