Isaca CISM - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/cism.html
Which of the following is MOST important to include in an information security policy?
Best practices
Management objectives
Baselines
Maturity levels
How does an incident response team BEST leverage the results of a business impact analysis (BIA)?
Assigning restoration priority during incidents
Determining total cost of ownership (TCO)
Evaluating vendors critical to business recovery
Calculating residual risk after the incident recovery phase
The incident response team can best leverage the results of a business impact analysis (BIA) by assigning restoration priority during incidents. A BIA is a process that identifies and evaluates the criticality and dependency of the organization's business functions, processes, and resources, and the potential impacts and consequences of their disruption or loss. The BIA results provide the basis for determining the recovery objectives, strategies, and plans for the organization's business continuity and disaster recovery.
By using the BIA results, the incident response team can prioritize the restoration of the most critical and time-sensitive business functions, processes, and resources, and allocate the appropriate resources, personnel, and time to minimize the impact and duration of the incident.
Determining total cost of ownership (TCO) (B) is not a relevant way to leverage the results of a BIA, as it is not directly related to incident response. TCO is a financial metric that estimates the total direct and indirect costs of owning and operating an asset or a system over its lifecycle. TCO may be useful for evaluating the cost-effectiveness and return on investment of different security solutions or alternatives, but it does not help the incident response team to respond to or recover from an incident.
Evaluating vendors critical to business recovery ?is also not a relevant way to leverage the results of a BIA, as it is not a primary responsibility of the incident response team. Evaluating vendors critical to business recovery is a part of the vendor management process, which involves selecting, contracting, monitoring, and reviewing the vendors that provide essential products or services to support the organization's business continuity and disaster recovery. Evaluating vendors critical to business recovery may be done before or after an incident, but not during an incident, as it does not contribute to the incident response or restoration activities.
Calculating residual risk after the incident recovery phase (D) is also not a relevant way to leverage the results of a BIA, as it is not a timely or effective use of the BIA results. Residual risk is the risk that remains after the implementation of risk treatment or mitigation measures. Calculating residual risk after the incident recovery phase may be done as a part of the incident review or improvement process, but not during the incident response or restoration phase, as it does not help the incident response team to resolve or contain the incident.
References:
CISM Review Manual, 16th Edition, Chapter 4: Information Security Incident Management, Section:
Incident Response Plan, Subsection: Business Impact Analysis, page 182-1831
Which of the following is MOST important when designing an information security governance framework?
Aligning with the information security strategy
Assessing the availability of information security resources
Aligning with industry best practice frameworks
Assessing the current state of information security
A global organization is planning to expand its operations into a new country with stricter data protection regulations than those in the headquarters' home country.
Which of the following is the BEST approach for adopting these new requirements?
Adjust organization-wide security polices to align with regulations of the new country.
Ensure local operations comply with geographical data protection laws of the headquarters.
Work with legal to interpret the local regulatory requirements and implement applicable controls.
Procure cybersecurity insurance that covers potential breaches and incidents in the new country.
Which of the following is an information security manager's MOST important course of action after receiving information about a new cybersecurity threat?
Assess the impact of the new threat on the organization in the event of materialization.
Update correlation rules for log monitoring to detect the possible emerging threat.
Report the threat to senior management immediately to enable an informed decision.
Review the enterprise architecture (EA) for vulnerabilities exploited by the threat.
Which of the following presents the GREATEST challenge when assessing the impact of emerging risk?
Complexity of the emerging risk
Insufficient data related to the emerging risk
Outdated risk management strategy
Lack of resources to perform risk assessments
The greatest challenge in assessing emerging risk is insufficient data (B). Emerging risks, by definition, lack historical incidents, loss data, and proven impact metrics, making accurate assessment difficult. CISM emphasizes that uncertainty and data scarcity are inherent challenges in emerging risk management.
Complexity (A) and resource constraints (D) are common issues, but without sufficient data, even skilled analysts and mature processes struggle to estimate likelihood and impact. An outdated strategy (C) affects overall effectiveness but does not specifically hinder impact assessment as much as data scarcity does.
References:
ISACA CISM Review Manual (Risk management-emerging risks, uncertainty, and assessment
challenges)
CISM Exam Content Outline (Domain 1).
Which of the following MUST happen immediately following the identification of a malware incident?
Preparation
Recovery
Containment
Eradication
Containment is the action that MUST happen immediately following the identification of a malware incident because it aims to isolate the affected systems or networks from the rest of the environment and prevent the spread or escalation of the malware. Containment can involve disconnecting the systems or networks from the internet, blocking or filtering certain ports or protocols, or creating separate VLANs or subnets for the isolated systems or networks. Containment is part of the incident response process and should be performed as soon as possible after detecting a malware incident. Preparation (A) is the phase that happens before the identification of a malware incident, where the organization establishes the incident response plan, team, roles, resources, and tools. Preparation is essential for ensuring the readiness and capability of the organization to respond to malware incidents effectively and efficiently. Recovery (B) is the phase that happens after the containment and eradication of a malware incident, where the organization restores the normal operations of the systems or networks, verifies the functionality and security of the systems or networks, and implements the preventive and corrective measures to avoid or mitigate future malware incidents. Recovery is the final phase of the incident response process and should be performed after ensuring that the malware incident is fully resolved and the systems or networks are clean and secure. Eradication (D) is the phase that happens after the containment of a malware incident, where the organization removes the malware and its traces from the systems or networks, identifies the root cause and impact of the malware incident, and collects and preserves the evidence for analysis and investigation. Eradication is an important phase of the incident response process, but it does not happen immediately after the identification of a malware incident.
References:
1: CISM Review Manual 15th Edition, page 308-3091;
2: Cybersecurity Incident Response Exercise Guidance - ISACA2
The BEST way to integrate information security governance with corporate governance is to ensure:
the information security steering committee monitors compliance with security policies.
management teams embed information security into business processes.
awareness programs include industry best practice for information security governance.
the information security program is included in regular external audits.
The best way to integrate information security governance with corporate governance is for management teams to embed information security into business processes. The CISM Review Manual explains that aligning security objectives and activities with organizational goals and business processes ensures that security is a core part of business operations and strategy, not an isolated activity.
References:
ISACA CISM Review Manual, 16th Edition, Page 38-39, "Integration of Information Security with Business Processes".
An information security manager learns that business unit leaders are encouraging increased use of social media platforms to reach customers.
Which of the following should be done FIRST to help mitigate the risk of confidential information being disclosed by employees on social media?
Establish an organization-wide social media policy.
Develop sanctions for misuse of social media sites.
Monitor social media sites visited by employees.
Restrict social media access on corporate devices.
An organization-wide social media policy is a document that defines the rules and guidelines for using social media platforms within the organization. It covers topics such as who can use social media, what they can post, how they should protect confidential information, and what are the consequences for violating the policy. An organization-wide social media policy helps to mitigate the risk of confidential information being disclosed by employees on social media by providing a clear and consistent framework for managing social media activities.
References:
1: CISM Review Manual (Digital Version), page 271
2: CISM Review Manual (Print Version), page 271
Which of the following processes BEST supports the evaluation of incident response effectiveness?
Root cause analysis
Post-incident review
Chain of custody
Incident logging
A post-incident review (PIR) is the process of evaluating the effectiveness of the incident response after the incident has been resolved. A PIR aims to identify the strengths and weaknesses of the response process, the root causes and impacts of the incident, the lessons learned and best practices, and the recommendations and action plans for improvement. A PIR can help an organization enhance its incident response capabilities, reduce the likelihood and severity of future incidents, and increase its resilience and maturity.
A PIR is the best process to support the evaluation of incident response effectiveness, because it provides a systematic and comprehensive way to assess the performance and outcomes of the response process, and to identify and implement the necessary changes and improvements. A PIR involves collecting and analyzing relevant data and feedback from various sources, such as incident logs, reports, evidence, metrics, surveys, interviews, and observations. A PIR also involves comparing the actual response with the expected or planned response, and measuring the achievement of the response objectives and the satisfaction of the stakeholders 3. A PIR also involves documenting and communicating the findings, conclusions, and recommendations of the evaluation, and ensuring that they are followed up and implemented.
The other options are not as good as a PIR in supporting the evaluation of incident response effectiveness, because they are either more specific, limited, or dependent on a PIR. A root cause analysis (RCA) is a technique to identify the underlying factors or reasons that caused the incident, and to prevent or mitigate their recurrence. An RCA can help an organization understand the nature and origin of the incident, and to address the problem at its source, rather than its symptoms. However, an RCA is not sufficient to evaluate the effectiveness of the response process, because it does not cover other aspects, such as the response performance, outcomes, impacts, lessons, and best practices. An RCA is usually a part of a PIR, rather than a separate process. A chain of custody (CoC) is a process of maintaining and documenting the integrity and security of the evidence collected during the incident response. A CoC can help an organization ensure that the evidence is reliable, authentic, and admissible in legal or regulatory proceedings. However, a CoC is not a process to evaluate the effectiveness of the response process, but rather a requirement or a standard to follow during the response process. A CoC does not provide any feedback or analysis on the response performance, outcomes, impacts, lessons, or best practices. An incident logging is a process of recording and tracking the details and activities of the incident response.
An incident logging can help an organization monitor and manage the response process, and to provide an audit trail and a source of information for the evaluation. However, an incident logging is not a process to evaluate the effectiveness of the response process, but rather an input or a tool for the evaluation. An incident logging does not provide any assessment or measurement on the response performance, outcomes, impacts, lessons, or best practices.
References:
1: CISM Review Manual 15th Edition, Chapter 5, Section 5.5
2: Post-Incident Review: A Guide to Effective Incident Response
3: Post-Incident Review: A Guide to Effective Incident Response : CISM Review Manual 15th Edition, Chapter 5, Section 5.5 : CISM Review Manual 15th Edition, Chapter 5, Section 5.5 : CISM Review Manual
15th Edition, Chapter 5, Section 5.
4 : CISM Review Manual 15th Edition, Chapter 5, Section 5.3
Showing 10 of 1,583 questions · Unlock the full set