CISM Exam Question 321

During which phase of an incident response plan is the root cause determined?
  • CISM Exam Question 322

    Business objectives and organizational risk appetite are MOST useful inputs to the development of information security:
  • CISM Exam Question 323

    A recent application security assessment identified a number of low- and medium-level vulnerabilities. Which of the following stakeholders is responsible for deciding the appropriate risk treatment option?
  • CISM Exam Question 324

    When assigning a risk owner, the MOST important consideration is to ensure the owner has:
  • CISM Exam Question 325

    Which is following should be an information security manager's PRIMARY focus during the development of a critical system storing highly confidential data?