Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 587 discussion

Actual exam question from Isaca's CISM
Question #: 587
Topic #: 1
[All CISM Questions]

Which of the following is the MOST appropriate resource to determine whether or not a particular solution should utilize encryption based on its location and data classification?

  • A. Guidelines
  • B. Procedures
  • C. Standards
  • D. Policies
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
mohit05
Highly Voted 1 year, 10 months ago
Selected Answer: D
D. Policies would be the most appropriate resource to determine whether or not a particular solution should utilize encryption based on its location and data classification. Policies are a set of rules and regulations that dictate how data should be handled and protected. They typically outline specific requirements for data encryption, and may take into account factors such as the location of the data and its classification level.
upvoted 9 times
...
Raj91188
Most Recent 2 months ago
Selected Answer: C
C. Standards. Standards provide detailed, specific requirements and criteria for implementing controls such as encryption based on factors like data classification and location. Policies provide high-level guidance but typically do not include specific implementation details like when and where encryption should be applied.
upvoted 2 times
...
03allen
5 months ago
Selected Answer: C
I think it's C. Policies will give very high-level direction, but for a single system, it will follow the security standard.
upvoted 2 times
...
maisarajarrah
10 months, 2 weeks ago
Selected Answer: C
it's C
upvoted 1 times
...
babadook13
1 year ago
Selected Answer: C
it's C
upvoted 2 times
...
koala_lay
1 year, 1 month ago
Selected Answer: D
The most appropriate resource to determine whether or not a particular solution should utilize encryption based on its location and data classification would be policies. Policies are high-level documents that define an organization's overarching principles, goals, and guidelines. They establish the strategic direction and provide a framework for decision-making. In the context of information security, policies often outline the organization's stance on various security measures, including encryption.
upvoted 2 times
...
Bl1024
1 year, 2 months ago
Selected Answer: C
Policies are not sesitive to specific solutions, standards are used to determine the rules regarding specific systems in accordance with the more general dictation of policies
upvoted 2 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: D
Policies provide high-level guidance and direction for an organization's approach to security and data protection. They set the overarching rules and principles that govern how data should be handled, including when encryption should be used. Policies often take into account the organization's risk tolerance, legal requirements, and industry best practices. Guidelines, procedures, and standards are typically more detailed documents that stem from policies
upvoted 1 times
...
wickhaarry
1 year, 3 months ago
C https://frsecure.com/blog/differentiating-between-policies-standards-procedures-and-guidelines/
upvoted 2 times
...
richck102
1 year, 4 months ago
C. Standards
upvoted 1 times
...
wello
1 year, 5 months ago
Selected Answer: C
tandards provide specific requirements and specifications that organizations are expected to adhere to, and they may include guidance on encryption based on data classification and location.
upvoted 2 times
...
Saisharan
1 year, 5 months ago
Option D. Policies provide the high-level guidance and direction for information security, including determining when encryption should be used based on factors such as location and data classification.
upvoted 1 times
...
Gr3yGh0sT
1 year, 6 months ago
Selected Answer: D
The MOST appropriate resource to determine whether or not a particular solution should utilize encryption based on its location and data classification is policies. Policies are high-level documents that define the organization's overall security goals and objectives. They typically include requirements for encryption, as well as other security controls. When determining whether or not to encrypt a particular solution, organizations should first consult their policies. The policy will specify the types of data that must be encrypted, as well as the encryption requirements for those data types.
upvoted 2 times
...
MyKasala
1 year, 9 months ago
Selected Answer: C
I guess C
upvoted 2 times
[Removed]
1 year, 8 months ago
Standards can include guidelines for securing information systems, defining access controls, encrypting data, or protecting sensitive information
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...