CISM Exam Question 141
A new regulatory requirement affecting an organization's information security program is released. Which of the following should be the information security manager's FIRST course of action?
CISM Exam Question 142
A newly appointed information security manager has been asked to update all security-related policies and procedures that have been static for five years or more. What is the BEST next step?
CISM Exam Question 143
An information security manager has identified a major security event with potential noncompliance implications. Who should be notified FIRST?
CISM Exam Question 144
Which of the following would BEST support a business case to implement an anti-ransomware solution?
CISM Exam Question 145
Which of the following is MOST important when defining how an information security budget should be allocated?