exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 27 discussion

Actual exam question from Isaca's CISM
Question #: 27
Topic #: 1
[All CISM Questions]

Which of the following BEST enables effective information security governance?

  • A. Security-aware corporate culture
  • B. Advanced security technologies
  • C. Periodic vulnerability assessments
  • D. Established information security metrics
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
andyprior
3 months, 3 weeks ago
Selected Answer: A
Effective information security governance requires a holistic approach that integrates policies, processes, and people. Among the options provided, a security-aware corporate culture is the most comprehensive enabler of effective governance because it ensures that security practices and principles are embedded throughout the organization.
upvoted 1 times
...
hesbee
10 months, 4 weeks ago
Selected Answer: A
Metrics only shows if the information security governance is effective or not BUT doesn't enable its effectiveness. A security-aware corporate culture on the other hand will enable or aid the effectiveness of the information security governance thereby resulting in good metrics.
upvoted 1 times
...
Manix
1 year, 1 month ago
Selected Answer: D
Pages 64, General metric considerations: "Metrics serve only one purpose: to provide the information neceessary for making decisions"
upvoted 1 times
...
Viperhunter
1 year, 3 months ago
Selected Answer: A
A security-aware corporate culture is foundational to effective information security governance. It involves creating a mindset within the organization where employees at all levels understand the importance of security, follow security policies, and actively contribute to the protection of information assets. A strong security culture promotes accountability, awareness, and a collective commitment to information security. While advanced security technologies (option B), periodic vulnerability assessments (option C), and established information security metrics (option D) are essential components of a comprehensive security program, a security-aware corporate culture provides the organizational context and human factor necessary for successful information security governance.
upvoted 3 times
AlexJacobson
1 year, 3 months ago
Dude, you rely too much on ChatGPT. It can easily point you in the wrong direction.
upvoted 2 times
...
...
richck102
1 year, 10 months ago
A. Security-aware corporate culture
upvoted 1 times
...
[Removed]
2 years ago
The question asks 'Enable" not measure i think A is correct here
upvoted 3 times
...
STUDYER2
2 years, 1 month ago
metrics is the only objective measurement here..
upvoted 2 times
...
Antonivs
2 years, 2 months ago
Selected Answer: A
A & D are good ones
upvoted 1 times
...
aokisan
2 years, 2 months ago
Selected Answer: A
culture enforces governance.
upvoted 1 times
...
AngeloC
2 years, 2 months ago
D - I think that establishing (and monitoring) security metrics is the best way to evaluate the effectiveness of security governance
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago