CISM Information Security Programme • Set 3
CISM Information Security Programme Practice Test 3 — 15 questions with explanations. Free, no signup.
An organization is implementing a security controls framework based on NIST SP 800-53. The CISO wants to prioritize controls that will provide the greatest risk reduction for critical assets. Which approach should be used to select the initial set of controls?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.