P.S. Fast2testがGoogle Driveで共有している無料かつ新しいCISMダンプ:https://drive.google.com/open?id=13N9cWFyEZuSI0-ncuF416bMxSqXQ6WlX
ほとんどの労働者の基準はますます高くなることがわかっているため、CISMガイドの質問にも高い目標を設定しています。市場にある他の練習教材とは異なり、当社のトレーニング教材はお客様の関心を他のポイントの前に置き、私たちをずっと高度な学習教材にコミットさせます。これまで、最も複雑なCISMガイドの質問を簡素化し、簡単な操作システムを設計しました。CISM試験問題の自然でシームレスなユーザーインターフェイスは、より流fluentに成長しました。使いやすさ。
CISM認定は情報セキュリティマネジメントの分野において非常に尊敬される認定であり、業界の専門家のスキルと知識を正当化し、競争力を提供します。CISM試験は4つのドメインをカバーし、情報セキュリティガバナンス、リスクマネジメントとコンプライアンス、情報セキュリティプログラムの開発とマネジメント、および情報セキュリティインシデントマネジメントの候補者の理解を試験するために設計されています。この認定は、情報セキュリティマネジメントの分野でキャリアを進め、リーダーシップの役割を担いたい専門家に最適です。
Certified Information Security Manager(CISM)試験は、情報システム監査および制御協会(ISACA)が提供するプロフェッショナル認定試験です。CISM資格は、情報セキュリティ管理の専門家向けの認定として、グローバルに認知されています。CISM試験は、組織内で情報セキュリティプログラムを管理、設計、監視する個人の知識とスキルをテストするように設計されています。
時々重要な試験に合格するために大量の問題をする必要があります。我々の提供するソフトはこの要求をよく満たして専門的な解答の分析はあなたの理解にヘルプを提供できます。ISACAのCISM試験の資料のいくつかのバーションのデモは我々のウェブサイトで無料でダウンロードできます。あなたの愛用する版をやってみよう。我々の共同の努力はあなたに順調にISACAのCISM試験に合格させることができます。
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
質問 # 756
Which of the following would BEST assist an information security manager in measuring the existing level of development of security processes against their desired state?
正解:D
解説:
Section: INFORMATION SECURITY PROGRAM MANAGEMENT
Explanation:
The capability maturity model (CMM) grades each defined area of security processes on a scale of 0 to 5 based on their maturity, and is commonly used by entities to measure their existing state and then determine the desired one. Security audit reports offer a limited view of the current state of security. Balanced scorecard is a document that enables management to measure the implementation of their strategy and assists in its translation into action. Systems and business security architecture explain the security architecture of an entity in terms of business strategy, objectives, relationships, risks, constraints and enablers, and provides a business-driven and business-focused view of security architecture.
質問 # 757
An information security manager is asked to provide evidence that the organization is fulfilling its legal obligation to protect personally identifiable information (PII).
Which of the following would be
正解:C
質問 # 758
Which of the following is MOST critical for the successful implementation and maintenance of a security policy?
正解:B
解説:
Section: INCIDENT MANAGEMENT AND RESPONSE
Explanation
Explanation:
Assimilation of the framework and intent of a written security policy by the users of the system is critical to the successful implementation and maintenance of the security policy. A good password system may exist, but if the users of the system keep passwords written on their desk, the password is of little value. Management support and commitment is no doubt important, but for successful implementation and maintenance of security policy, educating the users on the importance of security is paramount. The stringent implementation, monitoring and enforcing of rules by the security officer through access control software, and provision for punitive actions for violation of security rules, is also required, along with the user's education on the importance of security.
質問 # 759
A small organization with limited budget hires a new information security manager who finds the same IT staff member is assigned the responsibility of system administrator, security administrator, database administrator, and application administrator. What is the manager's BEST course of action?
正解:D
質問 # 760
In a business proposal, a potential vendor promotes being certified for international security standards as a measure of its security capability.
Before relying on this certification, it is MOST important that the information security manager confirms that the:
正解:A
解説:
Before relying on a vendor's certification for international security standards, such as ISO/IEC 27001, it is most important that the information security manager confirms that the certification scope is relevant to the service being offered. The certification scope defines the boundaries and applicability of the information security management system (ISMS) that the vendor has implemented and audited. The scope should cover the processes, activities, assets, and locations that are involved in delivering the service to the client. If the scope is too narrow, too broad, or not aligned with the service, the certification may not provide sufficient assurance of the vendor's security capability and performance.
The current international standard was used to assess security processes (A) is an important factor, but not the most important one. The information security manager should verify that the vendor's certification is based on the latest version of the standard, which reflects the current best practices and requirements for information security. However, the standard itself is generic and adaptable, and does not prescribe specific security controls or solutions. Therefore, the certification does not guarantee that the vendor has implemented the most appropriate or effective security processes for the service being offered.
The certification will remain current through the life of the contract (B) is also an important factor, but not the most important one. The information security manager should ensure that the vendor's certification is valid and up to date, and that the vendor maintains its compliance with the standard throughout the contract period.
However, the certification is not a one-time event, but a continuous process that requires periodic surveillance audits and recertification every three years. Therefore, the certification does not ensure that the vendor's security capability and performance will remain consistent or satisfactory for the duration of the contract.
The certification can be extended to cover the client's business (D) is not a relevant factor, as the certification is specific to the vendor's ISMS and does not apply to the client's business. The information security manager should not rely on the vendor's certification to substitute or supplement the client's own security policies, standards, or controls. The information security manager should conduct a due diligence and risk assessment of the vendor, and establish a clear and comprehensive service level agreement (SLA) that defines the security roles, responsibilities, expectations, and metrics for both parties.
References = CISM Review Manual, 16th Edition, Chapter 3: Information Security Program Development and Management, Section: Information Security Program Management, Subsection: Procurement and Vendor Management, page 142-1431
質問 # 761
......
CISM模擬問題: https://jp.fast2test.com/CISM-premium-file.html
ちなみに、Fast2test CISMの一部をクラウドストレージからダウンロードできます:https://drive.google.com/open?id=13N9cWFyEZuSI0-ncuF416bMxSqXQ6WlX