exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 746 discussion

Actual exam question from Isaca's CISM
Question #: 746
Topic #: 1
[All CISM Questions]

Which of the following is a PRIMARY objective of an information security governance framework?

  • A. To provide the basis for action plans to achieve information security objectives organization-wide
  • B. To achieve the desired information security state as defined by business unit management
  • C. To align the relationships of stakeholders involved in developing and executing an information security strategy
  • D. To provide assurance that information assets are provided a level of protection proportionate to their inherent risk
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CarlPTY07
Highly Voted 1 year, 7 months ago
Selected Answer: A
ISACA defines this domain as follows: “Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with organizational goals and objectives.” Gregory, Peter H.; Gregory, Peter H.. CISM Certified Information Security Manager Bundle (p. 49). McGraw Hill LLC. Kindle Edition.
upvoted 12 times
...
Broesweelies
Highly Voted 1 year, 8 months ago
Selected Answer: D
The correct answer is D. To provide assurance that information assets are provided a level of protection proportionate to their inherent risk. The primary objective of an information security governance framework is to provide assurance that information assets are provided a level of protection proportionate to their inherent risk. This means that the framework should establish a clear set of policies, processes, and controls that are designed to ensure that information assets are protected in a manner that is commensurate with their level of risk. The framework should be designed to provide an appropriate balance between risk and cost, taking into account the value of the assets, the likelihood of a security breach, and the potential consequences of such a breach. By ensuring that information assets are protected in a manner that is proportionate to their inherent risk, the governance framework helps to ensure that the organization's information security objectives are met in a comprehensive and cost-effective manner.
upvoted 10 times
...
sursur
Most Recent 5 months, 2 weeks ago
Selected Answer: A
Most closely aligned with Option A. In option D is mentioning that providing level of protection proportionate to inherent risk. Not talking reducing risk to the acceptable level.
upvoted 1 times
...
Marcelus1714
8 months, 1 week ago
Selected Answer: A
I believe it's A. When I read D seems more talking about Risk management, not governance...
upvoted 2 times
...
AlexJacobson
8 months, 3 weeks ago
Selected Answer: A
I think A includes D.
upvoted 3 times
...
SilverFox
11 months ago
Selected Answer: A
Agree with CarlIPTY07
upvoted 1 times
...
koala_lay
1 year ago
Selected Answer: D
The primary objective of an information security governance framework is D. To provide assurance that information assets are provided a level of protection proportionate to their inherent risk. While the other options mentioned, such as providing the basis for action plans (Option A), achieving the desired information security state (Option B), and aligning stakeholder relationships (Option C), are important aspects of information security governance, they are not the primary objective. The primary objective is to ensure that information assets are adequately protected based on their risk profile.
upvoted 2 times
...
wickhaarry
1 year ago
A. To provide the basis for action plans to achieve information security objectives organization-wide Most Voted
upvoted 1 times
...
Bl1024
1 year ago
Selected Answer: A
Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with organizational goals and objectives.”
upvoted 1 times
...
richck102
1 year, 3 months ago
C. To align the relationships of stakeholders involved in developing and executing an information security strategy
upvoted 1 times
...
mad68
1 year, 5 months ago
Selected Answer: C
C. To align the relationships of stakeholders involved in developing and executing an information security strategy. An information security governance framework aims to establish a structure and processes for effectively managing and overseeing information security within an organization. It involves the alignment of various stakeholders, including senior management, business units, IT departments, and other relevant parties, to ensure that information security objectives are properly defined, implemented, and monitored.
upvoted 1 times
...
Souvik124
1 year, 8 months ago
The PRIMARY objective of an information security governance framework is to provide assurance that information assets are provided a level of protection proportionate to their inherent risk.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago