CISM Exam Question 316

An organization has been penalized by regulatory authorities for failing to notify them of a major security breach that may have compromised customer data. Which of the following is MOST likely in need of review and updating to prevent similar penalties in the future?
  • CISM Exam Question 317

    An information security manager has learned of an increasing trend in attacks that use phishing emails impersonating an organization's CEO in an attempt to commit wire transfer fraud. Which of the following is the BEST way to reduce the risk associated with this type of attack?
  • CISM Exam Question 318

    Which of the following should be given the HIGHEST priority during an information security post-incident review?
  • CISM Exam Question 319

    Which of the following should be an information security manager s MOST important consideration when determining the priority for implementing security controls?
  • CISM Exam Question 320

    Which of the following is the MOST important reason to ensure information security is aligned with the organization's strategy?