CISM Domain 3

CISM Domain 3

Professional Development

10 Qs

quiz-placeholder

Similar activities

NEOP Quiz

NEOP Quiz

Professional Development

15 Qs

Project Management

Project Management

Professional Development

10 Qs

SQ Smart Quiziz November 2024

SQ Smart Quiziz November 2024

Professional Development

10 Qs

PROJECT RISK MANAGEMENT

PROJECT RISK MANAGEMENT

Professional Development

10 Qs

M5C2

M5C2

Professional Development

10 Qs

M4Q2

M4Q2

Professional Development

10 Qs

AWS Certified Cloud Practitioner

AWS Certified Cloud Practitioner

Professional Development

15 Qs

CISA Quiz - Week1

CISA Quiz - Week1

Professional Development

10 Qs

CISM Domain 3

CISM Domain 3

Assessment

Quiz

Professional Development

Professional Development

Hard

Created by

John Lee

Used 8+ times

FREE Resource

10 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which element is the least probable to be included in the charter of an information security program?

Project Schedule

Roles and Responsibilities

Governance Structure

Statement of Scope

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

In an enterprise's information security program, which factor MOST helps in the integrating IT risk with other enterprise risks to achieve a comprehensive risk awareness?

Reporting structure

Third Party Risk management

Physical and Information Architecture

Development of effective metrics

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

An organization has outsourced most of its business applications to service providers. The various departments maintain separate lists of their service providers. Management is concerned that it may led to duplication and overlapping services. What is the FIRST step to take?

Develop a policy that requires all contracts with service providers to be reviewed by the legal department

Create a master list of all the service providers used

Require the procurement department to review all service contracts

Implement a technical control to discover what other third party services are in used

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the below document apply to the statement "Passwords should be at least 10 characters long and should contain at least 1 upper case letter, lower case letters, at least 1 number and 1 special characters with no consecutive repeating letters and numbers"

Procedure

Guideline

Policy

Standard

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the purpose of tailoring security awareness content for different audiences?

To increase the outreach to different audiences

To cater to the different learning styles of the groups of employees

To have varied messages so that it generate interest

To maximise the effort of content creation

6.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

The organization is embarking on an acquisition of a company. The CISO and the CRO would like to have a IS risk assessment before the deal is finalised. What is the reason?

To understand the cyber risk posture of the target company so that the organization is more prepared to deal with it

To discover compliance risks of the company

To know the cyber risks that may impact the valuation of the company

The CRO would like to know the risks before the company is acquire as he is in charge of all Enterprise Risks

7.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

The metric "Adverse Impact in Trend Analysis" (AITA) measures the trend in adverse impacts resulting from information security incidents over time. It evaluates the effectiveness of a risk management program in reducing the frequency and impact of incidents to an acceptable level. The metric provides a quantitative analysis of impacts in financial terms, offering insights into the success of the security program in meeting defined objectives and maintaining risk at acceptable levels.

A positive trend suggests an increase in adverse impacts demonstrating the success of the risk management efforts

If there is no increase or decrease in the trend over time, it means that there is no risk.

A negative trend is a reduction in adverse impact signalling an improvement in risk management

Both positive and negative trending allows for adjustment of the risk management program to align with organization objectives

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?