CISM › Information Security Programme
This domain covers building, governing and operating the information security programme: strategy, frameworks, control prioritisation, budget justification, roles and awareness. Questions are scenario-based, asking you to pick the FIRST or BEST action for a security manager, weighing business alignment, risk, resource limits and defence-in-depth sequencing over technical tooling detail.
CISM Information Security Programme — All 209 Questions
Every question in this domain with answers and detailed explanations.