CISM Exam Question 761
Senior management has endorsed a comprehensive information security policy. Which of the following should the organization do NEXT?
CISM Exam Question 762
In an organization with effective IT risk management, the PRIMARY reason to establish key risk indicators (KRIs) is to:
CISM Exam Question 763
The FIRST step in an incident response plan is to:
CISM Exam Question 764
Who is responsible for ensuring that information is classified?
CISM Exam Question 765
After a risk assessment, it is determined that the cost to mitigate the risk is much greater than the benefit to be derived. The information security manager should recommend to business management that the risk be:
