Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 515 discussion

Actual exam question from Isaca's CISM
Question #: 515
Topic #: 1
[All CISM Questions]

Which of the following should be the PRIMARY goal of an information security manager when designing information security policies?

  • A. Minimizing the cost of security controls
  • B. Reducing organizational security risk
  • C. Improving the protection of information
  • D. Achieving organizational objectives
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 9 months ago
Selected Answer: B
B. Reducing organizational security risk should be the primary goal of an information security manager when designing information security policies. This is because the primary purpose of information security policies is to protect the organization and its assets from potential threats and risks. By reducing organizational security risk, the organization is better protected and less likely to experience security incidents that can cause damage to the organization, its reputation and its customers. While minimizing cost and improving protection of information are important considerations, they should not take precedence over reducing risk as it is the ultimate goal of the information security policies. Achieving organizational objectives should be considered as well as it will help to align the security policies with the overall goals of the organization.
upvoted 9 times
Evedzy
11 months, 1 week ago
stop relying much on ChatGPT.
upvoted 2 times
...
...
AlexJacobson
Highly Voted 9 months, 4 weeks ago
Selected Answer: D
I'd say it's D for two reasons: 1) ISACA tends to emphasize that the whole point of security is to support the business and business goals and objectives. 2) Security risk is actually reduced through security controls, not policies. Policies are high-level stuff that provide a general idea what management wants to achieve.
upvoted 6 times
...
Booict
Most Recent 2 months, 2 weeks ago
Selected Answer: B
B for me.
upvoted 2 times
...
Thavee
7 months, 1 week ago
Selected Answer: D
D. Achieving organizational objectives . B is part of D.
upvoted 2 times
...
Salilgen
8 months, 2 weeks ago
Selected Answer: D
Organization can decide to accept risks to achieving its organizational objectives. Then, ISM's PRIMARY gol is not minimize organizational (option B) or information (option C) risks.
upvoted 1 times
...
SpaceMonkey1
10 months, 2 weeks ago
Selected Answer: B
B encompasses C and D
upvoted 1 times
...
POWNED
10 months, 3 weeks ago
Going to have to go with D on this one. ISACA heavily leans on aligning security goals with business objectives. And anyone using chatgpt to help them through these questions should just take your $600 for the certification cost and throw it in the trash.
upvoted 2 times
...
jcisco123
10 months, 4 weeks ago
Selected Answer: D
D. Achieving organizational objectives
upvoted 2 times
...
wickhaarry
1 year, 1 month ago
D. Achieving organizational objectives
upvoted 3 times
...
oluchecpoint
1 year, 2 months ago
Selected Answer: B
B. Reducing organizational security risk The PRIMARY goal of an information security manager when designing information security policies should be to reduce organizational security risk. Information security policies are put in place to protect an organization's sensitive data, systems, and assets from various threats and vulnerabilities. By focusing on reducing security risks, an organization can better protect itself from potential breaches, data leaks, and other security incidents.
upvoted 1 times
...
richck102
1 year, 4 months ago
D. Achieving organizational objectives
upvoted 5 times
...
mad68
1 year, 6 months ago
Selected Answer: C
the PRIMARY goal of an information security manager when designing information security policies is C. Improving the protection of information. This is because the primary goal of an information security policy is to protect the confidentiality, integrity and availability of information.
upvoted 1 times
...
Dravidian
1 year, 7 months ago
Reducing risk is the purpose of the entire exercise. However, it would've been justified in the initial steps and objectives will be set based on that. Leading into the reason for the security policies, which has to align with the objectives that have been already set. The fact that they will help reduce risk is given.
upvoted 3 times
...
Souvik124
1 year, 9 months ago
The PRIMARY goal of an information security manager when designing information security policies should be to improve the protection of information. While minimizing the cost of security controls, reducing organizational security risk, and achieving organizational objectives are important considerations, the ultimate goal of information security policies is to protect the confidentiality, integrity, and availability of organizational information. By improving information protection, an organization can reduce the risk of security incidents and minimize the impact of any incidents that do occur.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...