exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 525 discussion

Actual exam question from Isaca's CISM
Question #: 525
Topic #: 1
[All CISM Questions]

Which of the following is the PRIMARY purpose of implementing information security standards?

  • A. To provide a basis for developing information security policies
  • B. To provide step-by-step instructions for performing security-related tasks
  • C. To provide management direction with a specific security objective
  • D. To establish a minimum acceptable security baseline
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 5 months ago
Selected Answer: D
D. To establish a minimum acceptable security baseline is the primary purpose of implementing information security standards. Standards provide a framework for achieving a set of security objectives and establish a common set of security controls and guidelines that organizations should implement to protect their information systems. They are designed to be a starting point for organizations to build their own security programs and help ensure that the security measures in place are adequate to protect the organization's sensitive information and assets. Standards provide a common language and a consistent approach to security, which helps organizations to understand their security risks, identify vulnerabilities, and implement appropriate controls to mitigate those risks.
upvoted 6 times
...
Josef4CISM
Most Recent 3 days ago
Selected Answer: D
The answer is D: Standards define minimum security requirements tailored to a specific organization. An example could be the usage of TLS 1.2 or above or password complexity requirements. The answer is NOT B, since step by step instructions are covered by procedures. Procedures are one level below standards and contain detailed instructions on how to perform certain tasks (e.g., like a manual). The answer is NOT C, since security objectives are derived from business objectives (security as a supporting function for the business). There is no relation to standards - just forget about this answer option.
upvoted 1 times
...
TamerBeSafe
5 months, 2 weeks ago
Selected Answer: C
C. To provide management direction with a specific security objective. Information security standards are typically designed to provide a set of guidelines, principles, or requirements that help organizations establish and maintain a secure information environment. These standards offer management direction by outlining specific security objectives and expectations. They serve as a foundation for developing information security policies (Option A) and often include best practices and controls to establish a minimum acceptable security baseline (Option D). While some standards may include procedural details, their primary focus is to provide overarching guidance and direction for achieving security goals within an organization
upvoted 1 times
...
maisarajarrah
6 months, 2 weeks ago
Selected Answer: D
To establish a minimum acceptable security baseline
upvoted 1 times
...
Cert_IT
10 months ago
Selected Answer: C
C. To provide management direction with a specific security objective.
upvoted 1 times
AlexJacobson
5 months, 2 weeks ago
WHY?? HOW?
upvoted 2 times
...
...
richck102
1 year ago
D. To establish a minimum acceptable security baseline
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago