exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 446 discussion

Actual exam question from Isaca's CISM
Question #: 446
Topic #: 1
[All CISM Questions]

Which of the following is MOST important to the effectiveness of an information security program?

  • A. The program is aligned to legal and regulatory requirements
  • B. The program is aligned to a security control framework
  • C. Annual audits of the program are conducted
  • D. Users are trained on security policies and procedures
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 7 months ago
Selected Answer: B
B. The program is aligned to a security control framework. A security control framework provides a structured approach for identifying, assessing, and mitigating information security risks. It is important to align an information security program to a security control framework in order to ensure that the program is comprehensive and that all necessary security controls are in place. The alignment with a security control framework also helps to ensure that the organization is compliant with relevant laws, regulations and industry standards.
upvoted 9 times
...
Manzer
Highly Voted 1 year, 8 months ago
Selected Answer: D
Train the users.
upvoted 9 times
...
Josef4CISM
Most Recent 1 month, 3 weeks ago
Selected Answer: D
Aligning the security framework to best practices is advisable as it will increase the credibility of your programme. BUT it is not as important as user training and awareness. You can have the best security programme in the world - it will be useless, if users dont care.
upvoted 3 times
...
03allen
3 months, 3 weeks ago
Selected Answer: D
Educating people will improve the effectiveness. B is too specific, we don't always say security control framework imo.
upvoted 2 times
...
oluchecpoint
7 months ago
Selected Answer: D
User awareness is the key
upvoted 2 times
...
POWNED
8 months, 1 week ago
Selected Answer: D
Want to chime in and state that when a question involves MOST and training/education is one of the answers, 95% of the time the correct answer is training/education. Why? Because we all know users are the largest threat to any business.
upvoted 2 times
...
jcisco123
8 months, 1 week ago
Selected Answer: A
Legal requirements are the most important. If your program is not aligned to it, the company could be in serious trouble!
upvoted 1 times
...
[Removed]
9 months, 3 weeks ago
Selected Answer: D
Users knowing what do is more important
upvoted 2 times
...
AaronS1990
1 year ago
Selected Answer: D
D for the reasons explained below
upvoted 3 times
...
AaronS1990
1 year ago
This is definitely D. Once again the people saying B have used chatGPT and haven't got a clue what they're on about. How can you cay that it is more useful for a security program to follow a framework (of which there are several) than it is for you employees to be educated and properly trained?
upvoted 6 times
oluchecpoint
11 months, 1 week ago
you are asking question not giving a reason for your option
upvoted 1 times
...
...
richck102
1 year, 2 months ago
B. The program is aligned to a security control framework
upvoted 1 times
...
Saisharan
1 year, 3 months ago
Option B
upvoted 1 times
...
mad68
1 year, 3 months ago
Selected Answer: B
ISACA emphasizes the importance of aligning the information security program with recognized security control frameworks. This alignment helps organizations establish a structured and comprehensive approach to information security management. ISACA's CISM (Certified Information Security Manager) certification focuses on information security management and requires candidates to have a deep understanding of establishing, managing, and governing information security programs. One of the key aspects of a successful information security program, as emphasized by ISACA, is the alignment to a security control framework.
upvoted 5 times
...
meelaan
1 year, 4 months ago
Selected Answer: A
legal and regulatory requirements are the most important
upvoted 1 times
...
aokisan
1 year, 8 months ago
Selected Answer: C
audit is effective for enhance.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago