CISM Exam Question 761

Senior management has endorsed a comprehensive information security policy. Which of the following should the organization do NEXT?
  • CISM Exam Question 762

    In an organization with effective IT risk management, the PRIMARY reason to establish key risk indicators (KRIs) is to:
  • CISM Exam Question 763

    The FIRST step in an incident response plan is to:
  • CISM Exam Question 764

    Who is responsible for ensuring that information is classified?
  • CISM Exam Question 765

    After a risk assessment, it is determined that the cost to mitigate the risk is much greater than the benefit to be derived. The information security manager should recommend to business management that the risk be: