CISM Exam Question 451

When responding to a security incident, information security management and the affected business unit management cannot agree whether to escalate the incident to senior management.
Which of the following would MOST effectively prevent this situation from recurring?
  • CISM Exam Question 452

    An organization has received complaints from users that some of their files have been encrypted.
    These users are receiving demands for money to decrypt the files. Which of the following would be the BEST course of action?
  • CISM Exam Question 453

    Which of the following is the MOST important reason to consider organizational culture when developing an information security program?
  • CISM Exam Question 454

    A new information security manager finds that the organization tends to use short-term solutions to address problems. Resource allocation and spending are not effectively tracked, and there is no assurance that compliance requirements are being met. What should be done FIRST to reverse this bottom-up approach to security?
  • CISM Exam Question 455

    Which of the following is the MOST essential element of an information security program?