CISM (Certified Information Security
manager) Exam Questions and Answers
Characteristics of a good information security risk
management plan - Correct Answer ✅ 1. Should be linked
to business objectives
2. Should incorporate existing risk management practices
Steps that IS manager should follow to plan a risk
management program? - Correct Answer ✅ 1. Establish
program context and purpose
2. developing a program scope statement and charter
3. identify and classify information assets and determine
asset owners
4. define what the risk management plan will achieve for the
organization
5. determining the methodology to be used
6. establish a program implementation team with people
from key departments
Risk Management Plan - Establishing program context and
purpose - Correct Answer ✅ This first step in risk
management planning It includes defining the purpose of the
program, setting objectives and outcomes for the program,
,CISM (Certified Information Security
manager) Exam Questions and Answers
and determining what the acceptable levels of risk are for the
organization. developing a program scope statement and
charter is ranked
Risk Management Plan - developing a program scope
statement and charter - Correct Answer ✅ This is the
second step in risk management program planning. In this
step, you create a scope statement that defines the risk
management responsibilities of each department in the
organization, the specific actions each member of a
department must take, and the scope of authority that rests
with the information security manager, and other risk
management roles.
Risk Management Plan - Identify and classify information
assets and determine asset owners - Correct Answer ✅
This is the third step in risk management program planning.
All information assets are identified and classified to ensure
they are easily identifiable and classified. Owners are
identified and assigned so that someone is accountable for
each asset.
, CISM (Certified Information Security
manager) Exam Questions and Answers
Risk Management Plan - Define what the risk management
plan will achieve for the organization - Correct Answer ✅
This is the fourth step in risk management program planning.
Here, the objectives for the risk management program are set
based on the risk analysis.
Risk Management Plan - Determining the methodology to be
used - Correct Answer ✅ This is the fifth step in risk
management program planning. In this step, you determine
what methods you'll use to manage the risks you've
identified and prioritized. This involves assessing the
effectiveness of the methods currently in use and identifying
and evaluating alternative methods.
Establish a program implementation team with people from
key departments - Correct Answer ✅ This is the sixth step
in risk management program planning. A team is established
with people from all departments. This helps in aligning the
program to every activity that the organization performs.
IR Management Program Roles - Correct Answer ✅ 1.
Governing board and senior management
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Allivia. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $15.49. You're not tied to anything after your purchase.