Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 612 discussion

Actual exam question from Isaca's CISM
Question #: 612
Topic #: 1
[All CISM Questions]

Which of the following is the MOST effective way to help staff members understand their responsibilities for information security?

  • A. Require staff to sign confidentiality agreements.
  • B. Require staff to participate in information security awareness training.
  • C. Communicate disciplinary processes for policy violations.
  • D. Include information security responsibilities in job descriptions.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 9 months ago
Selected Answer: B
B it is boys
upvoted 6 times
...
Booict
Most Recent 2 months, 3 weeks ago
Selected Answer: B
B for me
upvoted 1 times
...
usercism007
3 months, 3 weeks ago
Selected Answer: B if security awareness training mentions and security responsibilities in the job description are options. Pick Security Awareness training over others.
upvoted 1 times
...
usercism007
4 months, 2 weeks ago
Selected Answer: B This question makes many people confused. "Security awareness training" precedes over "responsibilities in job description" as employees don't read or remember it after they join. "
upvoted 1 times
...
Thavee
7 months, 1 week ago
Selected Answer: D
Each employee has different responsibility. Training is holistic of building security awareness. I think we went thru the similar question before.
upvoted 1 times
...
AlexJacobson
9 months, 4 weeks ago
Selected Answer: B
"Help understand" is the key part. So training.
upvoted 1 times
AlexJacobson
9 months, 4 weeks ago
On second thought, it says "responsibilities" - understand what they are responsible for while doing their jobs. So then it is D - job description.
upvoted 1 times
...
...
CISSPST
1 year, 1 month ago
Selected Answer: D
Including security responsibilities in JDs not only develops awareness of their responsibilities but also aids in compliance enforcement. Think of it like this: your JD is specific to you. Awareness training is less specific as it is created for a group. What is more likely to get you attention? What will you take more seriously?
upvoted 1 times
...
Kunzle
1 year, 2 months ago
B. Awareness training is designed to educate staff about various security threats and best practices. It provides an ongoing mechanism to ensure that staff are informed about their roles, the potential risks, and how to address them.
upvoted 1 times
Thavee
7 months, 1 week ago
Nop, finance department and sales department have got few fundamental security, but they are totally different in details.
upvoted 1 times
...
...
oluchecpoint
1 year, 2 months ago
Selected Answer: B
B. Require staff to participate in information security awareness training. While the other options (A, C, and D) can be important components of an organization's information security program, providing staff with information security awareness training is generally the most effective method for ensuring that they understand their responsibilities and the importance of information security. Training helps employees learn about various security threats, best practices, and how to recognize and respond to security risks. It also helps create a security-conscious culture within the organization.
upvoted 1 times
...
Vesta1807
1 year, 3 months ago
Selected Answer: D
Peter Gregory CISM Book :- A small but effective way to drive a culture of security is to add in specific language regarding the responsibilities that each role plays in protecting the organization’s data and systems used in storing, processing, and transmitting that data. While option B (training) is something most of us may lean towards. D is the right answer.
upvoted 2 times
xcjxcj
8 months, 2 weeks ago
For everyone JD? Including CFO, CEO?
upvoted 1 times
...
...
richck102
1 year, 4 months ago
B. Require staff to participate in information security awareness training.
upvoted 1 times
...
karanvp
1 year, 4 months ago
B may not be correct answer, because each one's responsibilities (may be unique) can't convey in common awareness program. JD is specific; hence this would be better choice for detail each one's responsibilities
upvoted 1 times
...
Gr3yGh0sT
1 year, 6 months ago
Selected Answer: B
This is the way.
upvoted 1 times
...
g4g
1 year, 10 months ago
Having it in my job description doesnt mean I understand it. Training is the way to understand.
upvoted 3 times
...
aokisan
1 year, 11 months ago
Selected Answer: B
effective way is training.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...