CISM Exam Question 131

An information security manager learns that a risk owner has approved exceptions to replace key controls with weaker compensating controls to improve process efficiency. Which of the following should be the GREATEST concern?
  • CISM Exam Question 132

    Which of the following is the sole responsibility of the client organization when adopting a Software as a Service (SaaS) model?
  • CISM Exam Question 133

    Which of the following is MOST helpful in determining an organization's current capacity to mitigate risks?
  • CISM Exam Question 134

    A user reports a stolen personal mobile device that stores sensitive corporate dat a. Which of the following will BEST minimize the risk of data exposure?
  • CISM Exam Question 135

    Which of the following is the MOST effective way to prevent information security incidents?