Which of the following is the BEST way for an information security manager to learn of zero-day vulnerabilities?
The correct answer is B because cybersecurity threat intelligence groups provide the most effective source of information about zero-day vulnerabilities. Zero-day vulnerabilities are newly discovered or previously unknown weaknesses that may not yet have patches, signatures, or standard scanner checks. Threat intelligence sources can provide early warnings, exploit details, indicators of compromise, affected technologies, attacker tactics, and recommended mitigations. Signature-based malware detection tools are limited because they depend on known malicious patterns and may not detect new threats. Penetration testing can identify weaknesses, but it is periodic and limited to the scope of the test. Vulnerability scanning tools are useful for identifying known vulnerabilities, but they may not detect zero-day vulnerabilities until detection logic is available. In CISM risk management, organizations should maintain awareness of emerging threats and adapt controls as the threat environment changes. Therefore, cybersecurity threat intelligence groups are the best source for learning of zero-day vulnerabilities.
Which of the following should be done FIRST to determine the impact of a new regulatory requirement for cloud services?
The correct answer is C because before assessing impact, performing a gap analysis, or conducting a risk assessment, the organization must first determine whether the new regulatory requirement applies to its cloud services, data, jurisdictions, customers, industry, and processing activities. Applicability establishes whether the regulation is relevant and which systems, processes, contracts, business units, or data types are in scope. A risk assessment is important after applicability is confirmed, but performing it too early may waste resources or miss the correct scope. Reviewing the asset inventory may support scoping, but it should follow or support the applicability analysis. A gap analysis compares current practices against requirements, but this cannot be done properly until the organization confirms that the requirement applies and understands its scope. CISM risk management emphasizes identifying legal, regulatory, and contractual obligations as part of risk and compliance management. Therefore, determining applicability is the first step in understanding the impact of a new regulatory requirement.
During which of the following development phases is it MOST challenging to implement security controls?
The development phase is the stage of the system development life cycle (SDLC) where the system requirements, design, architecture, and implementation are performed. The development phase is most challenging to implement security controls because it involves complex and dynamic processes that may not be well understood or documented. Security controls are essential for ensuring the confidentiality, integrity, and availability of the system and its data, as well as for complying with regulatory and contractual obligations. However, security controls may also introduce additional costs, risks, and constraints to the development process, such as:
Increased complexity and overhead of testing, verification, validation, and maintenance
Reduced flexibility and agility of changing requirements or design
Increased dependency on external vendors or third parties for security services or products
Increased vulnerability to errors, defects, or vulnerabilities in the code or configuration
Increased difficulty in measuring and reporting on security performance or effectiveness
Therefore, implementing security controls in the development phase requires careful planning, coordination, communication, and collaboration among all stakeholders involved in the SDLC. It also requires a clear understanding of the security objectives, scope, criteria, standards, policies, procedures, roles, responsibilities, and resources for the system. Moreover, it requires a proactive approach to identifying and mitigating potential threats or risks that may affect the security of the system.
Reference= CISM Manual1, Chapter 3: Information Security Program Development (ISPD), Section 3.1: System Development Life Cycle (SDLC)2
1: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles2: https://store.isaca.org/s/store#/store/browse/cat/a2D4w00000Ac6NNEAZ/tiles
A recent application security assessment identified a number of low- and medium-level vulnerabilities. Which of the following stakeholders is responsible for deciding the appropriate risk treatment option?
Verified Answer: According to the CISM Review Manual, 15th Edition, Chapter 3, Section 3.2.1.3, 'The appropriate risk treatment option is decided by the chief information security officer (CISO) or the designated risk owner.'1
The CISO is the senior executive who is responsible for overseeing and managing the information security program of an organization. The CISO has the authority and expertise to assess the risks, determine the risk appetite and tolerance levels, and select the most suitable risk treatment options for each risk. The CISO also has the accountability and responsibility for implementing, monitoring, and reporting on the risk treatment activities.
Which of the following should be the PRIMARY objective of an information security governance framework?
According to the Certified Information Security Manager (CISM) Study Manual, 'The primary objective of information security governance is to provide a framework for managing and controlling information security practices and technologies at an enterprise level. Its goal is to manage and reduce risk through a process of identification, assessment, and management of those risks.'
While demonstrating senior management commitment, compliance with industry best practices, and ensuring user compliance with policies are all important aspects of information security governance, they are not the primary objective. The primary objective is to manage and reduce risk by establishing a framework for managing and controlling information security practices and technologies at an enterprise level.
Certified Information Security Manager (CISM) Study Manual, 15th Edition, Page 60.
Ashley Wilson
10 days agoJason Brown
22 days agoJessica Flores
1 month agoRonald Smith
2 months agoAnthony Phillips
2 months agoWilliam Morris
3 months agoEric Lewis
3 months agoRachel Morgan
4 months agoLisa Collins
4 months agoAngela Clark
3 months agoEric Rogers
3 months agoSandra Hall
3 months agoStephen Bell
4 months agoVesta
5 months agoFausto
5 months agoKatina
5 months agoClorinda
5 months agoVeronique
6 months agoEden
6 months agoChrista
6 months agoMilly
6 months agoYan
7 months agoBethanie
7 months agoRegenia
7 months agoNieves
7 months agoEvangelina
8 months agoLynelle
8 months agoRamonita
8 months agoCiara
8 months agoJesse
9 months agoDaniela
9 months agoAnnmarie
9 months agoBernadine
9 months agoBernardo
10 months agoCelestina
10 months agoTaryn
10 months agoHelaine
10 months agoMarti
11 months agoCarlene
11 months agoLavelle
11 months agoYesenia
12 months agoThomasena
12 months agoLouvenia
1 year agoKanisha
1 year agoVinnie
1 year agoJackie
1 year agoArt
1 year agoLon
1 year agoCaprice
1 year agoNoah
1 year agoFernanda
1 year agoYong
2 years agoAshley
2 years agoBarrett
2 years agoDavida
2 years agoLauran
2 years agoLuis
2 years agoShaunna
2 years agoLaquita
2 years agoOlive
2 years agoLili
2 years agoBrittani
2 years agoJannette
2 years agoLeonor
2 years agoJohnetta
2 years agoDyan
2 years agoGlory
2 years agoLavera
2 years agoTroy
2 years agoFallon
2 years agoOllie
2 years agoStephanie
2 years agoArlen
2 years agoStephaine
2 years agoJunita
2 years agoBea
2 years agoMicah
2 years agoLavelle
2 years agoThurman
2 years agoAlline
2 years agoJerry
2 years agoChun
2 years ago