CISM Exam Question 391

When a security standard conflicts with a business objective, the situation should be resolved by:
  • CISM Exam Question 392

    An organization has learned of a security breach at another company that utilizes similar technology. The FIRST thing the information security manager should do is:
  • CISM Exam Question 393

    Which of the following metrics is the MOST appropriate for measuring how well information security is performing in dealing with outside attacks?
  • CISM Exam Question 394

    An information security manager is analyzing a risk that is believed to be severe, but lacks numerical evidence to determine the impact the risk could have on the organization. In this case the information security manager should:
  • CISM Exam Question 395

    Which of the following is the MOST appropriate method to protect a password that opens a confidential file?