P.S. MogiExamがGoogle Driveで共有している無料かつ新しいCISMダンプ:https://drive.google.com/open?id=1r0I9uo_sibOu6iEgwkDfJvN5LmsIpxFb
MogiExamの助けのもとで君は大量のお金と時間を费やさなくても復楽にISACAのCISM認定試験に合格のは大丈夫でしょう。ソフトの問題集はMogiExamが実際問題によって、テストの問題と解答を分析して出来上がりました。MogiExamが提供したISACAのCISMの問題集は真実の試験に緊密な相似性があります。
| Section | Weight | Objectives |
|---|---|---|
| Information Security Risk Management | 20% | - Evaluate information security controls to determine whether they are appropriate and effectively mitigate risk - Ensure that risk assessments, vulnerability assessments and threat assessments are performed consistently, at appropriate times, and to identify acceptable risk - Monitor and communicate the information security risk posture - Identify and/or recommend risk treatment options - Identify legal, regulatory, organizational and other applicable compliance requirements - Determine appropriate risk treatment options - Integrate risk management into business and IT processes - Establish and/or maintain a process for information asset identification, classification, risk assessment and ownership |
| Information Security Incident Management | 30% | - Establish and maintain an incident response plan to ensure an effective and timely response to information security incidents - Develop and implement processes to ensure the timely identification of information security incidents - Establish and maintain processes to investigate and document information security incidents - Establish and maintain an organizational definition of, and severity hierarchy for, information security incidents - Establish and maintain communication plans and processes to manage communication with internal and external entities - Organize, train and equip teams to effectively respond to information security incidents - Test, review and revise the incident response plan - Establish and maintain incident escalation and notification processes |
| Information Security Program Development and Management | 33% | - Establish and maintain information security architectures (people, process, technology) - Monitor and manage the information security program - Establish, communicate and maintain organizational information security standards, guidelines, procedures and other documentation - Identify, acquire and manage information security requirements for internal and external resources (services, partners, and suppliers) - Develop and maintain a security awareness, training and education program for all stakeholders - Establish and/or maintain the information security program in alignment with the information security strategy - Integrate information security requirements into organizational processes - Align the information security program with the operational objectives of other business functions |
| Information Security Governance | 17% | - Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with the goals and objectives of the organization - Establish and/or maintain information security policies to guide the development of standards, procedures and guidelines in alignment with enterprise goals and objectives - Develop business cases to support investments in information security - Establish, monitor, evaluate and report information security management metrics - Obtain commitment from senior management and other stakeholders for the information security program - Define and communicate the roles and responsibilities for information security throughout the organization - Identify internal and external influences to the organization that affect the information security strategy and program |
当面の実際のテストを一致させるために、MogiExamのISACAのCISM問題集の技術者はずべての変化によって常に問題と解答をアップデートしています。それに我々はいつもユーザーからのフィードバックを受け付け、アドバイスの一部をフルに活用していますから、完璧なMogiExamのISACAのCISM問題集を取得しました。MogiExamはそれを通じていつまでも最高の品質を持っています。
質問 # 155
Risk acceptance is a component of which of the following?
正解:B
解説:
Explanation
Risk acceptance is one of the alternatives to be considered in the risk mitigation process. Assessment and evaluation are components of the risk analysis process. Risk acceptance is not a component of monitoring.
質問 # 156
Which of the following is BEST to include in a business case when the return on investment (ROI) for an information security initiative is difficult to calculate?
正解:A
質問 # 157
Which of the following is the BEST way to assess the risk associated with using a Software as a Service (SaaS) vendor?
正解:A
解説:
Reviewing the results of the vendor's independent control reports is the best way to assess the risk associated with using a SaaS vendor because it provides an objective and reliable evaluation of the vendor's security controls and practices. Independent control reports, such as SOC 2 or ISO 27001, are conducted by third-party auditors who verify the vendor's compliance with industry standards and best practices. These reports can help the customer identify any gaps or weaknesses in the vendor's security posture and determine the level of assurance and trust they can place on the vendor.
Verifying that information security requirements are included in the contract is a good practice, but it does not provide sufficient assurance that the vendor is actually meeting those requirements. The contract may also have limitations or exclusions that reduce the customer's rights or remedies in case of a breach or incident.
Requesting customer references from the vendor is not a reliable way to assess the risk associated with using a SaaS vendor because the vendor may only provide positive or biased references that do not reflect the true experience or satisfaction of the customers. Customer references may also not have the same security needs or expectations as the customer who is conducting the assessment.
Requiring vendors to complete information security questionnaires is a useful way to gather information about the vendor's security policies and procedures, but it does not provide enough evidence or verification that the vendor is actually implementing and maintaining those policies and procedures. Information security questionnaires are also subject to the vendor's self-reporting and interpretation, which may not be accurate or consistent. References =
* CISM Review Manual 15th Edition, page 144
* SaaS Security Risk and Challenges - ISACA1
* SaaS Security Checklist & Assessment Questionnaire | LeanIX2
* Risk Assessment Guide for Microsoft Cloud3
質問 # 158
Which of the following will BEST facilitate timely and effective incident response?
正解:D
質問 # 159
Which of the following is the BEST strategy when determining an organization's approach to risk treatment?
正解:B
解説:
The best strategy for risk treatment is to prioritize controls that address the most critical risks, ensuring resources are focused where they will have the greatest impact on reducing the organization's overall risk exposure.
質問 # 160
......
当社MogiExamのCISM認定ファイルは、代表的な傑作であり、品質、サービス、革新をリードしています。テストCISM認定に関する最も重要な情報を収集し、業界の上級専門家および認定講師および著者によって作成およびコンパイルされた新しい知識ポイントを補足します。クライアントがCISMクイズ教材を効率的に学習し、CISM試験に合格できるように、実際の試験を刺激する機能などの補助機能を提供します。
CISM技術内容: https://www.mogiexam.com/CISM-exam.html
ちなみに、MogiExam CISMの一部をクラウドストレージからダウンロードできます:https://drive.google.com/open?id=1r0I9uo_sibOu6iEgwkDfJvN5LmsIpxFb