CISM Exam Question 36

Which of the following metrics would provide management with the MOST useful information about the effectiveness of a security awareness program?
  • CISM Exam Question 37

    Acceptable risk is achieved when:
  • CISM Exam Question 38

    One way to determine control effectiveness is by determining:
  • CISM Exam Question 39

    Which of the following is the MAIN reason for performing risk assessment on a continuous basis'?
  • CISM Exam Question 40

    What should be the PRIMARY basis for establishing a recovery time objective (RTO) for a critical business application?