CISM Exam Question 26

The PRIMARY objective of a security steering group is to:
  • CISM Exam Question 27

    What is the BEST course of action when an information security manager finds an external service provider has not implemented adequate controls for safeguarding the organization's critical data?
  • CISM Exam Question 28

    Organization XYZ, a lucrative, Internet-only business, recently suffered a power outage that lasted two hours.
    The organization's data center was unavailable in the interim. In order to mitigate risk in the MOST cost-efficient manner, the organization should:
  • CISM Exam Question 29

    Which of the following is the BEST mechanism to determine the effectiveness of the incident response process?
  • CISM Exam Question 30

    When implementing information security in system development projects, which of the following is the MOST effective approach for an information security manager with limited resources?