CISM Exam Question 36
Which of the following metrics would provide management with the MOST useful information about the effectiveness of a security awareness program?
CISM Exam Question 37
Acceptable risk is achieved when:
CISM Exam Question 38
One way to determine control effectiveness is by determining:
CISM Exam Question 39
Which of the following is the MAIN reason for performing risk assessment on a continuous basis'?
CISM Exam Question 40
What should be the PRIMARY basis for establishing a recovery time objective (RTO) for a critical business application?
